CVE-2026-75006 | Roundcube Webmail up to 1.6.17/1.7.2 CSS Sanitization server-side request forgery

SecurityVulns

A vulnerability was found in Roundcube Webmail up to 1.6.17/1.7.2. It has been classified as critical. The impacted element is an unknown function of the component CSS Sanitization. The manipulation leads to server-side request forgery.

This vulnerability is uniquely identified as CVE-2026-75006. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More