• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-54433: stored cross-site scripting in Roundcube Webmail

Attackers can execute JavaScript in the context of a logged-in Roundcube Webmail user and take over their session; this is CVE-2026-54433. The flaw affects Roundcube Webmail 1.6.0 through before 1.6.17 and 1.7.0 through before 1.7.2. A malicious plain-text email crafted by an attacker triggers the vulnerability when the recipient previews or opens the message, allowing script execution inside the victim's authenticated session.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
10CRITICAL
EPSS
0.00311
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists for this Roundcube Webmail stored XSS and the attack can run in a victim's authenticated session via message preview, so prioritize upgrading or applying mitigations now.

What is CVE-2026-54433?

Attackers can execute JavaScript in the context of a logged-in Roundcube Webmail user and take over their session; this is CVE-2026-54433. The flaw affects Roundcube Webmail 1.6.0 through before 1.6.17 and 1.7.0 through before 1.7.2. A malicious plain-text email crafted by an attacker triggers the vulnerability when the recipient previews or opens the message, allowing script execution inside the victim's authenticated session. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Which versions of Roundcube Webmail are affected?

BRANCHAFFECTEDFIXED
1.x1.6.0 – before 1.6.171.6.17
1.x1.7.0 – before 1.7.21.7.2

Is CVE-2026-54433 being exploited?

Public exploit code is available.

How to fix CVE-2026-54433

  1. Upgrade Roundcube Webmail to 1.6.17 or later, or 1.7.2 or later.
  2. If you cannot upgrade immediately, block or filter incoming suspicious plain-text email and disable automatic message previews.
  3. Restrict access to webmail to trusted networks or via VPN where feasible.
  4. Monitor webmail logs and user accounts for unusual activity and reset sessions for high-risk users after patching.

Frequently asked questions

Is CVE-2026-54433 being actively exploited?

Public exploit code is available for CVE-2026-54433, indicating the vulnerability can be weaponized; there is no CISA Known Exploited Vulnerabilities listing for it as of the provided date.

Which Roundcube Webmail versions are affected by CVE-2026-54433?

Roundcube Webmail versions 1.6.0 up to but not including 1.6.17, and 1.7.0 up to but not including 1.7.2, are affected.

Is there a patch for CVE-2026-54433?

Yes. The issue is fixed in Roundcube Webmail 1.6.17 and 1.7.2.

Does CVE-2026-54433 require authentication?

The JavaScript executes in the context of an authenticated Roundcube Webmail session when a user previews or opens the crafted message, so it impacts logged-in users.

References