https://seclists.org/oss-sec/2026/q1/196: CVE-2026-26079/CVE-2026-25916: Roundcube vulns prior to 1.5.13/1.6.13
Published Feb 23, 2026
·Updated
Affected Software
2 affected components
roundcube<1.5.13
roundcube<1.6.13
Frequently Asked Questions
1
What is the severity of CVE-2026-26079 and CVE-2026-25916?
CVE-2026-26079 is a CSS injection vulnerability and CVE-2026-25916 is a remote image blocking bypass vulnerability, both posing moderate risk to Roundcube users.
2
How do I fix CVE-2026-26079 and CVE-2026-25916?
To mitigate CVE-2026-26079 and CVE-2026-25916, upgrade to Roundcube versions 1.5.13 or 1.6.13 or later.
3
What are the impacts of CVE-2026-26079?
CVE-2026-26079 allows attackers to inject malicious CSS, potentially leading to unauthorized access or user data manipulation.
4
What are the impacts of CVE-2026-25916?
CVE-2026-25916 enables attackers to bypass remote image blocking protections through SVG content, which could be used for tracking or phishing.
5
Are previous versions of Roundcube affected by CVE-2026-26079 and CVE-2026-25916?
Yes, Roundcube versions prior to 1.5.13 and 1.6.13 are affected by these vulnerabilities and should be updated immediately.