• PATCH AVAILABLE

CVE-2026-75003: information disclosure in Roundcube Webmail

Attackers who can cause Roundcube Webmail to display a malicious SVG image can bypass the product's remote-image protections and expose sensitive data or escalate privileges. CVE-2026-75003 affects Roundcube Webmail 1.6.0 through 1.6.17 and 1.7.0 through 1.7.2. The flaw is triggered by a malformed url() reference inside an SVG FuncIRI that allows the image to be treated as safe; exploitation requires the application to render that crafted SVG (for example via a message or embedded image).

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00578
CWE
CWE-669
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a high-impact vulnerability that lets crafted SVGs evade image-blocking, so prioritize upgrading to the fixed releases or temporarily block SVG rendering from untrusted sources.

What is CVE-2026-75003?

Attackers who can cause Roundcube Webmail to display a malicious SVG image can bypass the product's remote-image protections and expose sensitive data or escalate privileges. CVE-2026-75003 affects Roundcube Webmail 1.6.0 through 1.6.17 and 1.7.0 through 1.7.2. The flaw is triggered by a malformed url() reference inside an SVG FuncIRI that allows the image to be treated as safe; exploitation requires the application to render that crafted SVG (for example via a message or embedded image).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Roundcube Webmail are affected?

BRANCHAFFECTEDFIXED
1.x1.6.0 – before 1.6.181.6.18
1.x1.7.0 – before 1.7.31.7.3

Is CVE-2026-75003 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-75003

  1. Upgrade Roundcube Webmail to 1.6.18 if on 1.6.x or to 1.7.3 if on 1.7.x.
  2. If immediate upgrade is not possible, disable SVG rendering and restrict remote image fetching in Roundcube and at the webserver or proxy level.
  3. Monitor mail rendering logs and user sessions for unusual image requests or rendering failures.
  4. Follow vendor guidance and test upgrades in a staging environment before deployment.

Frequently asked questions

Is CVE-2026-75003 being actively exploited?

There are no public reports of active exploitation and it is not listed in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-29.

Which Roundcube Webmail versions are affected by CVE-2026-75003?

Roundcube Webmail versions 1.6.0 through 1.6.17 and 1.7.0 through 1.7.2 are affected.

Is there a patch for CVE-2026-75003?

Yes. Fixed releases are Roundcube Webmail 1.6.18 and 1.7.3; upgrade to the appropriate fixed version.

Does CVE-2026-75003 require authentication?

Exploitation only requires the application to render the crafted SVG; special user privileges or interaction are not a prerequisite.

References