CVE-2026-48846

NameCVE-2026-48846
DescriptionIn Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4604-1, DSA-6301-1
Debian Bugs1137507

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
roundcube (PTS)bullseye1.4.15+dfsg.1-1+deb11u4vulnerable
bullseye (security)1.4.15+dfsg.1-1+deb11u9fixed
bookworm1.6.5+dfsg-1+deb12u8vulnerable
bookworm (security)1.6.5+dfsg-1+deb12u9fixed
trixie1.6.15+dfsg-0+deb13u1vulnerable
trixie (security)1.6.16+dfsg-0+deb13u1fixed
forky, sid1.6.16+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
roundcubesourcebullseye1.4.15+dfsg.1-1+deb11u9DLA-4604-1
roundcubesourcebookworm1.6.5+dfsg-1+deb12u9DSA-6301-1
roundcubesourcetrixie1.6.16+dfsg-0+deb13u1DSA-6301-1
roundcubesource(unstable)1.6.16+dfsg-11137507

Notes

https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
https://github.com/roundcube/roundcubemail/commit/852350486b88b35b8544e8a630fad89e99e2150a

Search for package or bug name: Reporting problems