Junglewise Threat Intelligence

CVE-2026-54433: Roundcube Webmail stored XSS in plain-text rendering

CVE-2026-54433 · Severity: high · CVSS 7.2 · Published 2026-07-14

Technologies: Roundcube Webmail. Vendors: Roundcube.

Executive brief

Roundcube Webmail, a widely used open-source email client, is affected by a security flaw that allows attackers to run malicious code in a user's browser. An attacker can trigger this by sending a specially crafted plain-text email; the malicious code executes automatically as soon as the victim opens or previews the message. This could allow an attacker to steal session information, access the victim's emails, or perform actions on their behalf without any further interaction.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Roundcube Webmail's plain-text rendering engine. The flaw is caused by improper neutralization of input during the processing of crafted plain-text email messages, allowing for 'zero-click' execution of attacker-controlled JavaScript when a user views or previews the message. The vulnerability affects versions prior to 1.6.17 and the 1.7.x branch prior to 1.7.2. An unauthenticated remote attacker can exploit this to perform actions in the context of the victim's session, such as session hijacking or unauthorized data access. The issue has been addressed in Roundcube versions 1.6.17 and 1.7.2.

Affected products

  • Roundcube Webmail before 1.6.17, 1.7.x before 1.7.2

Timeline

  • 2026-07-05: patched: Security updates 1.6.17 and 1.7.2 released by vendor
  • 2026-07-14: advisory: CVE-2026-54433 published

References

Related threats