Junglewise Threat Intelligence

CVE-2026-48849: Roundcube Webmail stored XSS in draft restore dialog subject field

CVE-2026-48849 · Severity: medium · CVSS 4.4 · Published 2026-05-25

Technologies: Roundcube Webmail. Vendors: Roundcube.

Executive brief

Roundcube Webmail, a widely used open-source web-based email client, is vulnerable to a security flaw that could allow an attacker to inject malicious scripts into shared mailboxes. By crafting a specific email subject line, an attacker could execute code in the browser of another user who interacts with a draft restoration prompt. This could lead to unauthorized access to email content or the hijacking of user sessions within the webmail interface.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The flaw is located in the draft restoration dialog, where the 'subject' field is not properly sanitized before being rendered in the UI. An authenticated attacker can exploit this by creating a draft with a malicious payload in the subject line; when another user (particularly in shared mailbox scenarios) attempts to restore that draft, the payload executes in their browser context. This allows for HTML/CSS injection and arbitrary JavaScript execution. The issue is addressed in versions 1.6.16 and 1.7.1.

Affected products

  • Roundcube Roundcube Webmail 1.6.x before 1.6.16, 1.7.x before 1.7.1

Timeline

  • 2026-05-24: patched: Roundcube released versions 1.6.16 and 1.7.1 to address the issue.
  • 2026-05-25: disclosed: CVE-2026-48849 was published.

References

Related threats