CVE-2026-48847: Roundcube Webmail

Low severity, CVSS 3.7. EPSS: 0.5% chance of exploitation in the next 30 days.

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

Affected products

  • Roundcube Webmail: from 1.6.0, before 1.6.16 (fixed in 1.6.16); from 1.7.0, before 1.7.1 (fixed in 1.7.1)

Published 2026-05-25. Last modified 2026-07-24.