CVE-2026-48843: Roundcube Webmail

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.

Affected products

  • Roundcube Webmail: from 1.6.14, before 1.6.16 (fixed in 1.6.16); from 1.7.0, before 1.7.1 (fixed in 1.7.1)

Published 2026-05-25. Last modified 2026-07-24.