Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-54433: Roundcube Webmail: Malicious Email Can Hijack User Sessions
CVE-2026-54433
CVE-2026-54433
Summary
If you use Roundcube Webmail, a hacker can create a malicious email that can take control of your account without you even opening it. This is a serious issue because it allows an attacker to access your email account and potentially steal sensitive information. To protect yourself, make sure to update to the latest version of Roundcube Webmail.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| roundcube | webmail |
< 1.6.17 >= 1.7.0, < 1.7.2 |
Original title
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the ...
Original description
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).
mitre CVSS3.1
7.2
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 14 Jul 2026 · Updated: 18 Jul 2026 · First seen: 14 Jul 2026