CVE-2026-48846 Details
Description
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
A vulnerability exists in Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1, allowing the remote image blocking feature to be bypassed. This is achieved by using a specially crafted CSS var() value in an email message, which could lead to information disclosure or an access control bypass.
Users are advised to update to Roundcube Webmail versions 1.6.16 or 1.7.1.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 25, 2026CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/roundcube/roundcubemail/commit/59cca80908a61e662c5f81741449e9aeb91e8abe | [email protected] | Source CodeVendor |
| https://github.com/roundcube/roundcubemail/commit/852350486b88b35b8544e8a630fad89e99e2150a | [email protected] | Source CodeVendor |
| https://github.com/roundcube/roundcubemail/releases/tag/1.6.16 | [email protected] | Release NotesVendor |
| https://github.com/roundcube/roundcubemail/releases/tag/1.7.1 | [email protected] | Release NotesVendor |
| https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-669 | Incorrect Resource Transfer Between Spheres | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Roundcube Webmail | >= 1.6, < 1.6.16 >= 1.7, < 1.7.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 25, 2026 | New CVE Received | [email protected] |
Volerion