DIRAS TAKE
Urgent: this is a high-impact vulnerability that lets crafted SVGs evade image-blocking, so prioritize upgrading to the fixed releases or temporarily block SVG rendering from untrusted sources.
What is CVE-2026-75003?
Attackers who can cause Roundcube Webmail to display a malicious SVG image can bypass the product's remote-image protections and expose sensitive data or escalate privileges. CVE-2026-75003 affects Roundcube Webmail 1.6.0 through 1.6.17 and 1.7.0 through 1.7.2. The flaw is triggered by a malformed url() reference inside an SVG FuncIRI that allows the image to be treated as safe; exploitation requires the application to render that crafted SVG (for example via a message or embedded image).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Roundcube Webmail are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.6.0 – before 1.6.18 | 1.6.18 |
| 1.x | 1.7.0 – before 1.7.3 | 1.7.3 |
Is CVE-2026-75003 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-75003
- Upgrade Roundcube Webmail to 1.6.18 if on 1.6.x or to 1.7.3 if on 1.7.x.
- If immediate upgrade is not possible, disable SVG rendering and restrict remote image fetching in Roundcube and at the webserver or proxy level.
- Monitor mail rendering logs and user sessions for unusual image requests or rendering failures.
- Follow vendor guidance and test upgrades in a staging environment before deployment.
Frequently asked questions
Is CVE-2026-75003 being actively exploited?
There are no public reports of active exploitation and it is not listed in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-29.
Which Roundcube Webmail versions are affected by CVE-2026-75003?
Roundcube Webmail versions 1.6.0 through 1.6.17 and 1.7.0 through 1.7.2 are affected.
Is there a patch for CVE-2026-75003?
Yes. Fixed releases are Roundcube Webmail 1.6.18 and 1.7.3; upgrade to the appropriate fixed version.
Does CVE-2026-75003 require authentication?
Exploitation only requires the application to render the crafted SVG; special user privileges or interaction are not a prerequisite.
References
- nvd.nist.gov/vuln/detail/CVE-2026-75003
- cve.org/CVERecord?id=CVE-2026-75003
- roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
- github.com/roundcube/roundcubemail/releases/tag/1.6.18
- github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b
- github.com/roundcube/roundcubemail/releases/tag/1.7.3
- github.com/roundcube/roundcubemail/commit/440277c32e6d84f3d116153af1cc8454361a8a56
- All Roundcube CVEs on CVE Radar
- CVEs published in September 2026