CVE-2026-75003: Medium severity Roundcube Roundcube Webmail vulnerability
Published Aug 17, 2026
·Updated
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.
Affected Software
1 affected component
Roundcube Roundcube Webmail<1.6.18, >1.7.0<1.7.3
Event History
Aug 17, 2026
CVE Published
via MITRE·12:50 PM
Data Sourced
via MITRE·12:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-75003?
CVE-2026-75003 has a medium severity rating of 5.8.
2
What types of vulnerabilities are associated with CVE-2026-75003?
CVE-2026-75003 can lead to information disclosure or privilege escalation due to unclosed url() in SVG images.
3
How do I fix CVE-2026-75003?
To fix CVE-2026-75003, you should update Roundcube Webmail to version 1.6.18 or 1.7.3 or later.
4
What versions of Roundcube are affected by CVE-2026-75003?
CVE-2026-75003 affects Roundcube Webmail versions prior to 1.6.18 and 1.7.x before 1.7.3.
5
Is there a risk of remote exploitation with CVE-2026-75003?
Yes, CVE-2026-75003 has a risk of remote exploitation due to its ability to evade remote image blocking.