Description
In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.
Published: 2026-05-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Roundcube Webmail versions 1.6.x between 1.6.14 and 1.6.16 and all 1.7.x releases before 1.7.1 contain a bug where the remote image blocking setting does not apply to URLs that point to local or private destinations. Because of this oversight, a crafted text/html email can cause the client to load a local resource that a normal user would not be able to access. The bug is documented as a CWE-669 vulnerability. When triggered, it can lead to the disclosure of sensitive information contained in local files and, in certain configurations, could allow an attacker to execute privileged operations or elevate privileges within the webmail system.

Affected Systems

The affected product is Roundcube Webmail. Vulnerable versions include any 1.6.x build from 1.6.14 up to and including 1.6.16, as well as any 1.7.x build earlier than 1.7.1. The fix is incorporated in release 1.6.16 and in release 1.7.1, which both restore proper handling of remote image blocking for local destinations.

Risk and Exploitability

The CVSS v3.1 score for this issue is 6.5, indicating a medium severity, and it applies to Roundcube Webmail. The EPSS score is unavailable, so the exploitation probability is currently unknown, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, involving an attacker sending a crafted HTML email that references a local or private URL. Because the flaw operates when a user opens the email, no special authentication is required beyond the ability to deliver a message to the target's webmail account, making the risk moderate but noticeable. Organizations should assess whether users can be tricked into opening such emails and apply available mitigations promptly.

Generated by OpenCVE AI on May 25, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Roundcube Webmail to version 1.6.16 or later, or 1.7.1 or later, to apply the remote image blocking fix.
  • Verify that the remote image blocking setting is enabled and correctly configured to block local resources.
  • Implement additional email content filtering to block or sanitize HTML messages that contain local or private URLs to prevent execution of the vulnerable behavior.

Generated by OpenCVE AI on May 25, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4604-1 roundcube security update
Debian DSA Debian DSA DSA-6301-1 roundcube security update
History

Tue, 26 May 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 25 May 2026 21:15:00 +0000

Type Values Removed Values Added
Title Local Image Blocking Bypass Leading to Information Disclosure and Potential Privilege Escalation in Roundcube Webmail

Mon, 25 May 2026 19:45:00 +0000

Type Values Removed Values Added
Description In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.
First Time appeared Roundcube
Roundcube webmail
Weaknesses CWE-669
CPEs cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
Vendors & Products Roundcube
Roundcube webmail
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Roundcube Webmail
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-27T03:55:26.292Z

Reserved: 2026-05-25T19:18:09.073Z

Link: CVE-2026-48845

cve-icon Vulnrichment

Updated: 2026-05-26T13:11:36.119Z

cve-icon NVD

Status : Deferred

Published: 2026-05-25T20:16:37.027

Modified: 2026-05-26T19:26:42.643

Link: CVE-2026-48845

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T21:00:11Z

Weaknesses
  • CWE-669

    Incorrect Resource Transfer Between Spheres