DIRAS TAKE
Urgent — this is a critical, unauthenticated vulnerability (CVSS 10.0) that can trigger SSRF or data disclosure from Roundcube installations; apply the vendor fixes 1.6.17 or 1.7.2 immediately or block HTML message rendering until patched.
What is CVE-2026-62643?
Unauthenticated attackers can cause Roundcube Webmail to fetch or leak internal resources by sending specially crafted HTML e‑mail that abuses insufficient CSS sanitization. CVE-2026-62643 affects Roundcube Webmail 1.6.0 through 1.6.16 and 1.7.0 through 1.7.1. An attacker only needs the ability to deliver a malicious HTML message to a mailbox on a vulnerable server; the flaw arises from stylesheet links in message HTML that can point at local network hosts and other internal endpoints. The weakness is classified as CWE-918 (Server-Side Request Forgery).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Which versions of Roundcube Webmail are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.6.0 – before 1.6.17 | 1.6.17 |
| 1.x | 1.7.0 – before 1.7.2 | 1.7.2 |
Is CVE-2026-62643 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-62643
- Upgrade Roundcube Webmail to 1.6.17 or 1.7.2.
- If you cannot upgrade immediately, disable automatic HTML rendering or strip external stylesheet links from incoming messages.
- Limit Roundcube server network access to internal resources and enforce egress filtering so rendered content cannot reach sensitive hosts.
- Monitor webmail logs for unusual external fetches and follow vendor guidance for additional mitigations.
Frequently asked questions
Is CVE-2026-62643 being actively exploited?
There are no public reports of exploitation of CVE-2026-62643 as of 2026-09-29.
Which Roundcube Webmail versions are affected by CVE-2026-62643?
Roundcube Webmail versions 1.6.0 through 1.6.16 and 1.7.0 through 1.7.1 are affected.
Is there a patch for CVE-2026-62643?
Yes; the issue is fixed in Roundcube Webmail 1.6.17 and 1.7.2.
Does CVE-2026-62643 require authentication?
No; the vulnerability can be triggered by an unauthenticated attacker who can deliver a crafted HTML message to a Roundcube mailbox.
References
- nvd.nist.gov/vuln/detail/CVE-2026-62643
- cve.org/CVERecord?id=CVE-2026-62643
- roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2
- github.com/roundcube/roundcubemail/releases/tag/1.7.2
- github.com/roundcube/roundcubemail/commit/6d69e094d55d3a9a84dfb36edf6ca985311f0c1c
- github.com/roundcube/roundcubemail/releases/tag/1.6.17
- github.com/roundcube/roundcubemail/commit/294c7da6e7284166f040cef8607b677d459e0786
- All Roundcube CVEs on CVE Radar
- CVEs published in September 2026