CVE-2026-48847
Published May 25, 2026
·Updated
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
Affected Software
1 affected component
Roundcube Roundcube Webmail>=1.6.0<1.6.16, >=1.7.0<1.7.1
Event History
May 25, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-48847?
The severity of CVE-2026-48847 is rated low with a score of 3.7.
2
How do I fix CVE-2026-48847?
To fix CVE-2026-48847, upgrade to Roundcube Webmail version 1.6.16 or 1.7.1 or later.
3
What types of attacks are associated with CVE-2026-48847?
CVE-2026-48847 is associated with pre-authentication arbitrary file deletion via session poisoning.
4
Which versions of Roundcube are affected by CVE-2026-48847?
Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1 are affected by CVE-2026-48847.
5
What can be compromised due to CVE-2026-48847?
Due to CVE-2026-48847, an attacker could potentially delete files on the server through session manipulation.