CVE-2026-54433: XSS
Published Jul 14, 2026
·Updated
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).
Affected Software
3 affected components
Roundcube Roundcube Webmail<1.6.17, >1.7.0<1.7.2
Roundcube Webmail<1.6.17
Roundcube Webmail>=1.7.0<1.7.2
Event History
Jul 14, 2026
CVE Published
via MITRE·04:18 PM
Data Sourced
via MITRE·04:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-54433?
The severity of CVE-2026-54433 is rated high with a score of 7.2.
2
How do I fix CVE-2026-54433?
To fix CVE-2026-54433, upgrade to Roundcube Webmail version 1.6.17 or 1.7.2 or later.
3
What type of vulnerability is CVE-2026-54433?
CVE-2026-54433 is a Stored Cross-Site Scripting (XSS) vulnerability.
4
What impact does CVE-2026-54433 have on users?
CVE-2026-54433 can lead to the execution of attacker-controlled JavaScript within the victim's authenticated session.
5
Which versions of Roundcube are affected by CVE-2026-54433?
Roundcube Webmail versions before 1.6.17 and 1.7.x before 1.7.2 are affected by CVE-2026-54433.