CVE-2026-75000EPSS p38.6%

CVE-2026-75000CVE-2026-75000

roundcube / webmail

Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

Scoring

CVSS 5.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
EPSS0.47% probability of exploitation · percentile 38.6% · 2026-10-05T12:00:23Z
Last modified2026-09-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.