CVE-2026-75003
Received Received - Intake

Remote Image Blocking Bypass via SVG in Roundcube Webmail

Vulnerability report for CVE-2026-75003, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: MITRE

Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-17
AI Q&A
2026-08-17
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
roundcube roundcube to 1.6.18 (exc)
roundcube roundcube From 1.7.0 (inc) to 1.7.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-669 The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3. It involves an unclosed url() function in a FuncIRI attribute of an SVG image, which bypasses remote image blocking. This could allow attackers to access sensitive information or escalate privileges.

Detection Guidance

This vulnerability involves an unclosed url() in a FuncIRI attribute of an SVG image in Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3. To detect it, inspect SVG image attributes in Roundcube emails for improperly closed url() functions within FuncIRI attributes. Check for emails containing SVG images with FuncIRI attributes that do not properly close url() calls.

Impact Analysis

The vulnerability may lead to information disclosure, where unauthorized parties could access confidential data. It could also enable privilege escalation, allowing attackers to gain higher access levels than intended.

Compliance Impact

This vulnerability could lead to information disclosure, which may impact compliance with GDPR (data protection) and HIPAA (health data privacy) by exposing sensitive user data through evasion of remote image blocking in Roundcube Webmail.

Mitigation Strategies

Update Roundcube Webmail to version 1.6.18 or later if using the 1.6.x branch, or to version 1.7.3 or later if using the 1.7.x branch. This addresses the SVG image attribute issue that could lead to information disclosure or privilege escalation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75003. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart