CVE-2026-48846
Published May 25, 2026
·Updated
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
Affected Software
1 affected component
Roundcube Roundcube Webmail<1.6.16, <1.7.1
Event History
May 25, 2026
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-48846?
CVE-2026-48846 has a medium severity rating of 6.5.
2
How do I fix CVE-2026-48846?
To fix CVE-2026-48846, upgrade Roundcube Webmail to versions 1.6.16 or 1.7.1 or later.
3
What does CVE-2026-48846 affect?
CVE-2026-48846 affects Roundcube Webmail versions prior to 1.6.16 and 1.7.1.
4
What type of vulnerability is CVE-2026-48846?
CVE-2026-48846 is a vulnerability related to the bypass of the remote image blocking feature in Roundcube Webmail.
5
What are the potential impacts of CVE-2026-48846?
CVE-2026-48846 may lead to information disclosure or access-control bypass.