CVE-2026-48847

NameCVE-2026-48847
DescriptionRoundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1137507

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
roundcube (PTS)bullseye1.4.15+dfsg.1-1+deb11u4vulnerable
bullseye (security)1.4.15+dfsg.1-1+deb11u8vulnerable
bookworm, bookworm (security)1.6.5+dfsg-1+deb12u8vulnerable
trixie (security), trixie1.6.15+dfsg-0+deb13u1vulnerable
sid1.6.16+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
roundcubesource(unstable)1.6.16+dfsg-11137507

Notes

https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
https://github.com/roundcube/roundcubemail/commit/703318e6a59515b73b0d8aa2a91e346b02f56baa

Search for package or bug name: Reporting problems