Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-54433: Roundcube Webmail: Malicious Email Can Hijack User Sessions

CVE-2026-54433 CVE-2026-54433
Summary

If you use Roundcube Webmail, a hacker can create a malicious email that can take control of your account without you even opening it. This is a serious issue because it allows an attacker to access your email account and potentially steal sensitive information. To protect yourself, make sure to update to the latest version of Roundcube Webmail.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
roundcube webmail < 1.6.17
>= 1.7.0, < 1.7.2
Original title
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the ...
Original description
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).
mitre CVSS3.1 7.2
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 14 Jul 2026 · Updated: 18 Jul 2026 · First seen: 14 Jul 2026