PT-2026-43107 · Unknown · Roundcube Webmail

·

CVE-2026-48844

·

Published

2026-05-24

·

Updated

2026-05-30

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Roundcube Webmail versions 1.6.x through 1.6.15 Roundcube Webmail versions 1.7.x through 1.7.0
Description Insecure code evaluation logic exists within the LDAP autovalues option, which could lead to code injection.
Recommendations Update to version 1.6.16 for the 1.6.x branch. Update to version 1.7.1 for the 1.7.x branch.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07446
CVE-2026-48844
OPENSUSE-SU-2026:10869-1
OPENSUSE-SU-2026:20852-1

Affected Products

Roundcube Webmail