Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Web Discovery

NVD - CVE-2026-26079

  • What: Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 is vulnerable to CSS injection due to mishandling of comments.
  • Impact: An attacker could inject malicious CSS code, potentially leading to information disclosure or other client-side attacks.
Read Full Article →

Vulnerabilities CVE-2026-26079 Detail Awaiting Analysis This CVE record has been marked for NVD enrichment efforts. Description Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: MITRE Base Score: 4.7 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N CVSS 2.0 Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected] . URL Source(s) Tag(s) https://github.com/roundcube/roundcubemail/commit/1f4c3a5af5033747f9685a8a395dbd8228d19816 MITRE https://github.com/roundcube/roundcubemail/commit/2b5625f1d2ef7e050fd1ae481b2a52dc35466447 MITRE https://github.com/roundcube/roundcubemail/commit/53d75d5dfebef235a344d476b900c20c12d52b01 MITRE https://github.com/roundcube/roundcubemail/commit/5a3315cce587e0be58335d11ff9a5571c90494a5 MITRE https://github.com/roundcube/roundcubemail/commit/bf89cbaa5897d8ad62e8057d9a3f6babb90b7954 MITRE https://github.com/roundcube/roundcubemail/commit/c15f5dbf093a497e19a749b20e7f8fb5a9c24cde MITRE https://github.com/roundcube/roundcubemail/releases/tag/1.5.13 MITRE https://github.com/roundcube/roundcubemail/releases/tag/1.6.13 MITRE https://roundcube.net/news/2026/02/08/security-updates-1.6.13-and-1.5.13 MITRE Weakness Enumeration CWE-ID CWE Name Source CWE-829 Inclusion of Functionality from Untrusted Control Sphere MITRE Change History 1 change records found show changes New CVE Received from MITRE 2/11/2026 12:16:28 AM Action Type Old Value New Value Added Description Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled. Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N Added CWE CWE-829 Added Reference https://github.com/roundcube/roundcubemail/commit/1f4c3a5af5033747f9685a8a395dbd8228d19816 Added Reference https://github.com/roundcube/roundcubemail/commit/2b5625f1d2ef7e050fd1ae481b2a52dc35466447 Added Reference https://github.com/roundcube/roundcubemail/commit/53d75d5dfebef235a344d476b900c20c12d52b01 Added Reference https://github.com/roundcube/roundcubemail/commit/5a3315cce587e0be58335d11ff9a5571c90494a5 Added Reference https://github.com/roundcube/roundcubemail/commit/bf89cbaa5897d8ad62e8057d9a3f6babb90b7954 Added Reference https://github.com/roundcube/roundcubemail/commit/c15f5dbf093a497e19a749b20e7f8fb5a9c24cde Added Reference https://github.com/roundcube/roundcubemail/releases/tag/1.5.13 Added Reference https://github.com/roundcube/roundcubemail/releases/tag/1.6.13 Added Reference https://roundcube.net/news/2026/02/08/security-updates-1.6.13-and-1.5.13 Quick Info CVE Dictionary Entry: CVE-2026-26079 NVD Published Date: 02/11/2026 NVD Last Modified: 02/11/2026 Source: MITRE

Share this article