CVE-2026-75000: Medium severity Roundcube Roundcube Webmail vulnerability
Published Aug 17, 2026
·Updated
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
Affected Software
2 affected components
Roundcube Roundcube Webmail<1.6.18
Roundcube Roundcube Webmail>1.7.0<1.7.3
Event History
Aug 17, 2026
CVE Published
via MITRE·12:45 PM
Data Sourced
via MITRE·12:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-75000?
The severity of CVE-2026-75000 is rated as medium with a score of 5.8.
2
What versions of Roundcube are affected by CVE-2026-75000?
CVE-2026-75000 affects Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3.
3
How do I fix CVE-2026-75000?
To fix CVE-2026-75000, upgrade to Roundcube Webmail version 1.6.18 or 1.7.3 or later.
4
What kind of impact does CVE-2026-75000 have?
CVE-2026-75000 may lead to remote image blocking bypass, potentially resulting in information disclosure or privilege escalation.
5
Is it possible to exploit CVE-2026-75000?
Yes, CVE-2026-75000 can be exploited due to improper HTML/CSS sanitization of the SVG animate 'by' attribute.