Executive brief
Roundcube Webmail, a widely used browser-based email client, contains a security flaw that could allow an unauthorized person to delete files on the server. By manipulating session data stored in Redis or Memcache, an attacker could potentially disrupt the service or delete critical application files without needing to log in. This could lead to service outages or data loss depending on which files are targeted.
Technical details
A vulnerability in Roundcube Webmail's session handling allows for pre-authentication arbitrary file deletion. The issue stems from a session poisoning bypass specifically affecting installations configured to use Redis or Memcache for session storage. An unauthenticated remote attacker can exploit this by poisoning session data to trigger the deletion of files on the underlying filesystem. The vulnerability was addressed by improving session validation and handling in 'rcmail_attachment_handler.php' and 'rcmail_sendmail.php'. Users are advised to upgrade to version 1.6.16 or 1.7.1.
Affected products
- Roundcube Webmail 1.6.x before 1.6.16, 1.7.x before 1.7.1
Timeline
- 2026-05-24: patched: Security updates 1.6.16 and 1.7.1 released
- 2026-05-25: disclosed: CVE-2026-48847 published
References
- https://github.com/roundcube/roundcubemail/commit/703318e6a59515b73b0d8aa2a91e346b02f56baa
- https://github.com/roundcube/roundcubemail/commit/a4eb375b98cc3d055de665c34efc729dd8ef272a
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.16
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.1
- https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1