What is CVE-2026-75003?
CVE-2026-75003 is a critical vulnerability in Roundcube Webmail where an unclosed `url()` in a FuncIRI attribute of an SVG image could bypass the remote image blocking feature. This may lead to information disclosure or privilege escalation, affecting versions before 1.6.18 and 1.7.x before 1.7.3. Immediate update to the patched versions is strongly recommended.
Azərbaycanca: CVE-2026-75003 Roundcube Webmail proqramında aşkar edilmiş kritik boşluqdur. SVG şəkillərində `url()` funksiyasının düzgün bağlanmaması uzaqdan şəkil bloklanması mexanizmini keçərək məlumat sızmasına və ya imtiyaz yüksəldilməsinə səbəb ola bilər. Bu zəiflik 1.6.18 və 1.7.3-dən əvvəlki versiyaları təsir edir, dərhal yeniləmə aparmaq tövsiyə olunur.
Related CVEs
link basis: shared vendor: Roundcube
FAQ2
Which versions of Roundcube are affected by CVE-2026-75003?
This vulnerability affects versions before 1.6.18 and 1.7.x versions before 1.7.3.
How can CVE-2026-75003 be exploited?
Due to an unclosed `url()` in SVG images, the remote image blocking feature can be bypassed, which may lead to information disclosure or privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.