Sceawere

Vulnerability Detail

CVE-2026-75006UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Roundcube CSS Sanitization Bypass SSRF

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.8
Creation Date
8h ago
Vendor
Roundcube
Product
Webmail
Attack Type
CWE-918 Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.8",
  "pubDate": "2026-08-17T13:16:55.240Z",
  "pubdate": "2026-08-17T13:16:55.240Z",
  "executiveSummary": "An insufficient Cascading Style Sheets sanitization vulnerability exists in Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3. This security flaw stems from inadequate remediation efforts addressing prior vulnerabilities tracked as CVE-2026-35540, CVE-2026-48843, and CVE-2026-62643.\nThe primary impact of this vulnerability encompasses Server-Side Request Forgery and unauthorized Information Disclosure. An attacker can exploit this flaw by leveraging malicious HTML e-mail messages containing crafted stylesheet links that target internal local network hosts otherwise inaccessible from external perimeters.\nThe affected systems include Roundcube Webmail deployments running vulnerable versions prior to 1.6.18 and 1.7.3. The risk implications involve potential internal network reconnaissance, exposure of sensitive internal services, and data leakage facilitated by the rendering engine executing unauthorized stylesheet requests.\nAttacker capabilities require the ability to deliver a specially crafted HTML e-mail message to a targeted user of the vulnerable Roundcube Webmail instance. Exploitation requirements rely on the victim opening the malicious message, which triggers the automated processing of the unsanitized CSS links within the email client context.",
  "technicalDetails": "The root cause of the vulnerability resides in insufficient Cascading Style Sheets sanitization logic within the HTML e-mail rendering pipeline of Roundcube Webmail. This issue persists as a result of incomplete or bypassable fixes implemented for previous security advisories identified as CVE-2026-35540, CVE-2026-48843, and CVE-2026-62643.\nThe vulnerable component is the HTML message parser and CSS sanitization module responsible for filtering malicious styles, external resource references, and embedded directives within incoming electronic mail messages.\nAffected versions comprise Roundcube Webmail instances prior to version 1.6.18 and version 1.7.x branches prior to 1.7.3. The vulnerability requires network exposure of the mail server and user interaction via the webmail interface, but does not necessitate prior authentication or elevated privileges for the external threat actor.\nThe exploitation method leverages crafted HTML e-mail payloads embedding malicious stylesheet links pointing toward internal network infrastructure or sensitive local hosts. When the victimized user opens the malicious e-mail within the vulnerable Roundcube Webmail client, the application parses the HTML content and attempts to resolve and load the specified CSS resources.\nThe attack flow proceeds step-by-step as follows: First, the threat actor transmits an e-mail containing malicious HTML with targeted stylesheet URI references to the victim. Second, the victim accesses the message using Roundcube Webmail. Third, the rendering engine processes the stylesheet references due to inadequate CSS sanitization rules. Fourth, the server or client initiates requests to the specified URIs, resulting in Server-Side Request Forgery against local network hosts or unauthorized Information Disclosure through out-of-band exfiltration channels."
}
CVE-2026-75006: Roundcube CSS Sanitization Bypass SSRF (MEDIUM Severity, CVSS: 5.8) - Sceawere