CVE-2026-74998: XSS
Published Aug 17, 2026
·Updated
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
Affected Software
1 affected component
Roundcube Roundcube Webmail<1.6.18, >1.7.0<1.7.3
Event History
Aug 17, 2026
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-74998?
CVE-2026-74998 has a high severity score of 7.2.
2
What type of vulnerabilities does CVE-2026-74998 involve?
CVE-2026-74998 involves information disclosure and cross-site scripting due to improper validation of CSS proxy responses.
3
How do I fix CVE-2026-74998?
To fix CVE-2026-74998, upgrade Roundcube Webmail to version 1.6.18 or 1.7.3 or later.
4
What versions of Roundcube are affected by CVE-2026-74998?
Roundcube versions prior to 1.6.18 and 1.7.x before 1.7.3 are affected by CVE-2026-74998.
5
What are the potential risks associated with CVE-2026-74998?
The potential risks include information disclosure and the possibility of XSS attacks via MIME sniffing.