Roundcube 1.7.2 / 1.6.17 CVE
Roundcube 1.7.2 and 1.6.17 (published 5 July 2026) fix two security vulnerabilities: a stored XSS via an unescaped attachment MIME type on the attachment-validation warning page (CVE-2026-54432) and an SSRF bypass via specific local address URLs (CVE-2026-54433). DirectAdmin servers running Roundcube webmail should update through CustomBuild.
Betroffene Versionen
1.7.2
Standard-Update-Befehl
cd /usr/local/directadmin/custombuild && ./build update_versions
Was das unter einer SharedLicense-Lizenz bedeutet
The stored XSS runs script in a webmail user's browser session, and the SSRF bypass can be used to reach internal addresses — both meaningful on shared mail servers.
Security updates 1.6.17 and 1.7.2 released
Free and open source webmail software for the masses, written in PHP
roundcube.net
Security updates 1.6.17 and 1.7.2 released
Published: 05 July 2026
We just published security updates to the 1.6 LTS and 1.7 versions of Roundcube Webmail. They both contain fixes for recently reported security vulnerabilities.
Security fixes
- Fix an infinite loop in TNEF (winmail.dat) decoder (#10193), reported by stafra.
- Fix various vulnerabilities in the password plugin using session-injected username, reported by Glendaenri and peppersghost.
- Fix stored XSS via unescaped attachment MIME type on the attachment-validation warning page [CVE-2026-54432], reported by Bohdan Kurinnoy, Samsung R&D Institute Ukraine (SRUKR).
- Fix SSRF bypass via specific local address URLs – two new cases, reported by Leenear.
- Fix zero-click stored XSS in plain-text rendering [CVE-2026-54433], reported by Bohdan Kurinnoy, Samsung R&D Institute Ukraine (SRUKR).
- Fix DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file, reported by h0rk1p.
See the full changelogs in the release notes on the Github download pages for the updated versions1.6.17 and 1.7.2.
We strongly recommend to update all productive installations of Roundcube 1.6.x and 1.7.x with this new versions.
Häufig gestellte Fragen
What is CVE-2026-54432?
What is CVE-2026-54433?
Which Roundcube versions fix these CVEs?
How do I update Roundcube on DirectAdmin?
System auf Schwachstellen prüfen
Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.
System prüfen