CVE-2026-54432: +moRoundcube XSS/SSRF/etc prior to 1.6.17/1.7.2
Published Jul 14, 2026
·Updated
Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.
Affected Software
2 affected components
Roundcube Roundcube Webmail<1.6.17
Roundcube Roundcube Webmail>1.7.0<1.7.2
Event History
Jul 14, 2026
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-54432?
The severity of CVE-2026-54432 is medium with a score of 4.7.
2
What kind of vulnerability is CVE-2026-54432?
CVE-2026-54432 is a Stored Cross-Site Scripting (XSS) vulnerability.
3
How do I fix CVE-2026-54432?
To fix CVE-2026-54432, upgrade Roundcube Webmail to version 1.6.17 or 1.7.2 or later.
4
What software is affected by CVE-2026-54432?
CVE-2026-54432 affects Roundcube Webmail versions prior to 1.6.17 and 1.7.x before 1.7.2.
5
What causes the CVE-2026-54432 vulnerability?
CVE-2026-54432 is caused by improper escaping of the attachment MIME type on the attachment-validation warning page.