Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insufficient CSS Sanitization in Roundcube Webmail Enables SSRF and Information Disclosure |
Mon, 17 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643. | |
| First Time appeared |
Roundcube
Roundcube webmail |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roundcube
Roundcube webmail |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-17T14:06:46.947Z
Reserved: 2026-08-17T12:56:46.553Z
Link: CVE-2026-75006
Updated: 2026-08-17T14:06:42.463Z
Status : Received
Published: 2026-08-17T13:16:55.240
Modified: 2026-08-17T14:20:22.273
Link: CVE-2026-75006
No data.
OpenCVE Enrichment
Updated: 2026-08-17T17:00:04Z