CVE-2026-48843 Details
Description
Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.
A vulnerability exists in Roundcube Webmail versions 1.6.x (1.6.14 to 1.6.16) and 1.7.x prior to 1.7.1) due to inadequate sanitization of Cascading Style Sheets (CSS) in HTML email messages. This flaw may result in Server-Side Request Forgery (SSRF) or unauthorized information disclosure, particularly if stylesheet links reference local network hosts. The vulnerability arises from an incomplete fix for a previous security issue (CVE-2026-35540).
Users are advised to update to Roundcube Webmail versions 1.6.16 or 1.7.1, both of which include the necessary security fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 25, 2026CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/roundcube/roundcubemail/commit/ab96c88bfd888866ec5e02190b19618db283923a | [email protected] | Source CodeVendor |
| https://github.com/roundcube/roundcubemail/commit/cb3fc9041e91640ba9ba49ee7b2147c176ebf5a1 | [email protected] | Source CodeVendor |
| https://github.com/roundcube/roundcubemail/releases/tag/1.6.16 | [email protected] | Release NotesVendor |
| https://github.com/roundcube/roundcubemail/releases/tag/1.7.1 | [email protected] | Release NotesVendor |
| https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Roundcube Webmail | >= 1.6.14, <= 1.6.16 (semver) < 1.7.1 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 25, 2026 | New CVE Received | [email protected] |
Volerion