Description
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
Published: 2026-08-17
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw localized in the "Add to address book" action of Roundcube Webmail. Malicious input placed into an address book entry is persisted and later executed in the browser of any user who views that entry, allowing an attacker to run arbitrary JavaScript in the victim’s context, potentially leading to session hijacking, data theft or defacement.

Affected Systems

Roundcube Webmail versions earlier than 1.6.18 and any 1.7 series release before 1.7.3 are affected. All editions that expose the Add to address book feature are vulnerable.

Risk and Exploitability

Based on the description, the likely attack vector is an authenticated user inserting malicious script into an address book entry, after which the script runs for anyone displaying that entry. The CVSS score of 5.4 indicates moderate severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, so the probability of widespread exploitation is uncertain, but storage XSS remains a significant threat to compromised web interfaces.

Generated by OpenCVE AI on August 17, 2026 at 15:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Roundcube Webmail to version 1.6.18 or any 1.7 series release equal to or newer than 1.7.3
  • Revoke or reset any compromised user accounts and enforce password changes to prevent credential‑based persistence
  • If immediate patching is not possible, disable the Add to address book feature to block the attack surface

Generated by OpenCVE AI on August 17, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4760-1 roundcube security update
Debian DSA Debian DSA DSA-6479-1 roundcube security update
History

Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Stored XSS in Roundcube Add to Address Book

Mon, 17 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
First Time appeared Roundcube
Roundcube webmail
Weaknesses CWE-79
CPEs cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
Vendors & Products Roundcube
Roundcube webmail
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Roundcube Webmail
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T14:33:47.482Z

Reserved: 2026-08-17T12:42:51.192Z

Link: CVE-2026-74999

cve-icon Vulnrichment

Updated: 2026-08-17T14:33:42.075Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-17T13:16:54.423

Modified: 2026-09-01T21:04:08.583

Link: CVE-2026-74999

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')