PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48843 Roundcube CVE debrief

Roundcube Webmail versions 1.6.14 through 1.6.16 and 1.7.x before 1.7.1 contain an insufficient CSS sanitization vulnerability in HTML email processing. The flaw allows malicious stylesheet links within email messages to trigger Server-Side Request Forgery (SSRF) or information disclosure when those links reference internal network hosts. This issue represents an incomplete remediation of CVE-2026-35540, indicating that prior security patches did not fully address the underlying sanitization weakness. The vulnerability carries a HIGH severity CVSS 3.1 score of 7.2 with network attack vector, low attack complexity, and no required privileges or user interaction. The chained confidentiality and integrity impacts combined with scope change to affected resources elevate risk for organizations using vulnerable Roundcube deployments.

Vendor
Roundcube
Product
Webmail
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-25
Original CVE updated
2026-07-24
Advisory published
2026-05-25
Advisory updated
2026-07-24

Who should care

Organizations operating Roundcube Webmail instances; security teams responsible for email gateway and webmail security; incident responders tracking SSRF exploitation patterns; system administrators managing on-premise or hosted email services

Technical summary

The vulnerability exists in Roundcube's HTML email rendering pipeline where Cascading Style Sheets are not sufficiently sanitized. Malicious emails containing stylesheet links pointing to internal network resources can cause the webmail server to fetch those resources, resulting in SSRF or information disclosure. The attack requires no authentication or user interaction, making it suitable for automated exploitation. The incomplete nature of the prior CVE-2026-35540 fix suggests the original patch addressed a specific attack vector but failed to comprehensively validate or restrict CSS link destinations.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade Roundcube Webmail to version 1.6.16 (for 1.6.x branch) or 1.7.1 (for 1.7.x branch) immediately
  • Review email filtering policies to restrict or sanitize external stylesheet references in HTML messages
  • Monitor webmail server logs for anomalous outbound requests triggered by email rendering processes
  • Assess network segmentation to limit exposure of internal services from webmail server hosts
  • Verify that prior patches for CVE-2026-35540 have been superseded by the updated fixes in 1.6.16/1.7.1

Evidence notes

CVE published 2026-05-25; modified 2026-05-26. Vendor security advisory dated 2026-05-24 precedes CVE publication. GitHub commits ab96c88bfd888866ec5e02190b19618db283923a and cb3fc9041e91640ba9ba49ee7b2147c176ebf5a1 identified as remediation commits. Releases 1.6.16 and 1.7.1 contain fixes. CWE-918 (Server-Side Request Forgery) classified as primary weakness.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48843 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48843

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48843 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48843

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.