What is CVE-2026-75000?
CVE-2026-75000 is an improper HTML/CSS sanitization vulnerability in Roundcube Webmail's SVG `animate` "by" attribute. This flaw allows remote image blocking bypass, potentially leading to information disclosure or privilege escalation. Affected versions include those before 1.6.18 and 1.7.x before 1.7.3; users should upgrade immediately to the patched versions.
Azərbaycanca: CVE-2026-75000 Roundcube Webmail-də SVG `animate` "by" atributunda düzgün olmayan HTML/CSS sanitizasiyası zəifliyidir. Bu, uzaqdan şəkil bloklanmasının (remote image blocking) bypass edilməsinə, nəticədə məlumat sızmasına (information disclosure) və ya imtiyaz yüksəldilməsinə (privilege escalation) səbəb ola bilər. Təsirə məruz qalan versiyalar 1.6.18-dən əvvəl və 1.7.3-dən əvvəl 1.7.x versiyalarıdır; dərhal yeni versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What functionality of Roundcube Webmail is affected by CVE-2026-75000?
CVE-2026-75000 is an improper HTML/CSS sanitization vulnerability in Roundcube Webmail's SVG `animate` "by" attribute.
What Roundcube versions are recommended to upgrade to for protection against CVE-2026-75000?
Versions before 1.6.18 and 1.7.x before 1.7.3 are affected; users should upgrade immediately to versions 1.6.18 or 1.7.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.