What is CVE-2026-75006?
In Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3, insufficient CSS sanitization in HTML emails can allow SSRF or Information Disclosure via stylesheet links pointing to local network hosts. This issue stems from incomplete fixes for a previous CVE. Affected installations should be updated to the patched versions immediately.
Azərbaycanca: Roundcube Webmail-in 1.6.18-dən əvvəlki və 1.7.3-dən əvvəlki 1.7.x versiyalarında HTML e-poçtlarda kifayət qədər CSS sanitizasiyası edilmir. Bu boşluq, üslub cədvəli (stylesheet) bağlantılarının lokal şəbəkə hostlarına yönləndirilməsi ilə SSRF və ya məlumat sızmasına səbəb ola bilər. Təsirə məruz qalan sistemlərdə dərhal göstərilən versiyalara yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Roundcube Webmail are affected by CVE-2026-75006?
Versions before 1.6.18 and 1.7.x versions before 1.7.3 are affected. Updating to the patched versions is recommended.
What type of attacks can CVE-2026-75006 lead to?
Due to insufficient CSS sanitization in HTML emails, stylesheet links can point to local network hosts, potentially leading to SSRF or Information Disclosure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.