Alerts This Week
Warning Icon 1 652
Alerts This Week
Warning Icon 1 652

openSUSE RoundcubeMail Important Pre-auth Injection Update 2026-20852-1

opensuse
Calendar Grey June 1, 2026
Dist Opensuse Esm H88
Update released for roundcubemail on openSUSE addresses multiple security issues and fixes bugs efficiently.
An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed.

Description

This update for roundcubemail fixes the following issues:

Changes in roundcubemail:

- update to 1.6.16

+ Fix potential too long value in IMAP ID command (#10136)

+ Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849] [bsc#1266337]

+ Security: Fix CSS injection bypass in HTML sanitizer via SVG 'animate attributeName="style"' [CVE-2026-48848] [bsc#1266336]

+ Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842] [bsc#1266329]

+ Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843] [bsc#1266331]

+ Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846] [bsc#1266334]

+ Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845] [bsc#1266333]

+ Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847] [bsc#1266335]

+...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

roundcubemail-1.6.16-bp160.1.1

References

* bsc#1266329

* bsc#1266331

* bsc#1266332

* bsc#1266333

* bsc#1266334

* bsc#1266335

* bsc#1266336

* bsc#1266337

References:

* https://www.suse.com/security/cve/CVE-2026-48842.html

* https://www.suse.com/security/cve/CVE-2026-48843.html

* https://www.suse.com/security/cve/CVE-2026-48844.html

* https://www.suse.com/security/cve/CVE-2026-48845.html

* https://www.suse.com/security/cve/CVE-2026-48846.html

* https://www.suse.com/security/cve/CVE-2026-48847.html

* https://www.suse.com/security/cve/CVE-2026-48848.html

* https://www.suse.com/security/cve/CVE-2026-48849.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20852-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here