Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26079

Опубликовано: 11 фев. 2026
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.

A flaw was found in Roundcube Webmail. This vulnerability allows for Cascading Style Sheets (CSS) injection, a technique where an attacker can inject malicious styling code into a web page. This occurs due to the application mishandling comments. Successful exploitation could lead to the disclosure of sensitive information.

Отчет

MODERATE: This flaw in Roundcube Webmail allows for Cascading Style Sheets (CSS) injection due to mishandled comments. This could potentially lead to information disclosure or defacement within the webmail interface when processing specially crafted email content.

Меры по смягчению последствий

For deployments of Roundcube Webmail, restrict access to the webmail interface to trusted networks or users. Additionally, users should exercise caution when opening emails from untrusted or suspicious sources, as this vulnerability requires processing of malicious CSS within email content.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2438807roundcubemail: Roundcube Webmail: Cascading Style Sheets (CSS) injection via mishandled comments

EPSS

Процентиль: 25%
0.00089
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 2 месяцев назад

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.

CVSS3: 4.7
nvd
около 2 месяцев назад

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.

CVSS3: 4.7
debian
около 2 месяцев назад

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading ...

CVSS3: 4.7
github
около 2 месяцев назад

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.

suse-cvrf
23 дня назад

Security update for roundcubemail

EPSS

Процентиль: 25%
0.00089
Низкий

4.7 Medium

CVSS3