CVE-2026-48844 Details
Description
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)
A code injection vulnerability has been identified in Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1. The issue arises from insecure code evaluation logic in the LDAP autovalues option, which could be exploited to inject malicious code. In versions 1.6.16 and 1.7.1, support for code evaluation in this context has been removed.
Users are advised to update to Roundcube Webmail versions 1.6.16 or 1.7.1. Instructions for downloading these versions are available on the Roundcube GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 25, 2026CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/roundcube/roundcubemail/commit/6a777d7394b763ce9acfce86c1a521e14a02d862 | [email protected] | Source CodeVendor |
| https://github.com/roundcube/roundcubemail/commit/ea1798a6fbf060abcc0ba73b2435036bf8016a5a | [email protected] | Source CodeVendor |
| https://github.com/roundcube/roundcubemail/releases/tag/1.6.16 | [email protected] | Release NotesVendor |
| https://github.com/roundcube/roundcubemail/releases/tag/1.7.1 | [email protected] | Release NotesVendor |
| https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-670 | Always-Incorrect Control Flow Implementation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Roundcube Webmail | >= 1.6, < 1.6.16 >= 1.7, < 1.7.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 25, 2026 | New CVE Received | [email protected] |
Volerion