Description
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
Published: 2026-08-17
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from incomplete sanitization of Cascading Style Sheets in HTML messages processed by Roundcube Webmail. When an email contains a link to an external stylesheet that points to a host on the local network, the webmail client can inadvertently request that file, exposing internal resources. The flaw is categorized as CWE‑918 (Improper Verification of Escape or Input Validation in Style Sheets).

Affected Systems

The affected vendor is Roundcube, for the Webmail product. Versions prior to 1.6.18 and 1.7.x before 1.7.3 are impacted. All installations that have not upgraded to these releases remain vulnerable.

Risk and Exploitability

The CVSS score of 5.8 reflects a medium severity assessment with potential for SSRF and local information disclosure. EPSS data is not available and the vulnerability is currently not listed in CISA's KEV catalog, suggesting limited public exploitation at this time. The most likely attack vector is remote: an adversary can send a crafted email that includes an external stylesheet link targeting an internal host, causing the victim's webmail session to trigger a request that could reveal internal services or data. Prompt application of the available patch is the recommended remediation.

Generated by OpenCVE AI on August 17, 2026 at 14:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Roundcube version 1.6.18 or 1.7.3 to address the insufficient CSS sanitization flaw.
  • Verify that the CSS sanitization configuration enforces a strict whitelist and rejects external stylesheet links.
  • As a temporary measure, configure your mail gateway or content filter to strip external stylesheet references from HTML emails until the official patch is deployed.

Generated by OpenCVE AI on August 17, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Insufficient CSS Sanitization in Roundcube Webmail Enables SSRF and Information Disclosure

Mon, 17 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
First Time appeared Roundcube
Roundcube webmail
Weaknesses CWE-918
CPEs cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
Vendors & Products Roundcube
Roundcube webmail
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

Roundcube Webmail
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T14:06:46.947Z

Reserved: 2026-08-17T12:56:46.553Z

Link: CVE-2026-75006

cve-icon Vulnrichment

Updated: 2026-08-17T14:06:42.463Z

cve-icon NVD

Status : Received

Published: 2026-08-17T13:16:55.240

Modified: 2026-08-17T14:20:22.273

Link: CVE-2026-75006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:00:08Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)