Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Roundcube Webmail could be made to run programs as your login if it opened a malicious website.. ========================================================================== Ubuntu Security Notice USN-8482-1 June 30, 2026 roundcube vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS Summary: Roundcube Webmail could be made to run programs as your login if it opened a malicious website. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapack Details: It was discovered that Roundcube Webmail was prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. An attacker could use this issue to execute arbitrary web script in the context of an affected user's session. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS roundcube 1.6.11+dfsg-1ubuntu0.26.04.1~esm1 Available with Ubuntu Pro roundcube-core 1.6.11+dfsg-1ubuntu0.26.04.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8482-1 CVE-2025-68461 . Roundcube Webmail has a Cross-Site Scripting issue that could allow attackers to execute scripts via malicious websites. Update now.. Roundcube Webmail, Ubuntu security, XSS vulnerability, web application security, system update. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Roundcube Webmail.. ========================================================================== Ubuntu Security Notice USN-8223-1 April 29, 2026 roundcube vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Roundcube Webmail. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapackage Details: It was discovered that Roundcube Webmail mishandled Punycode xn-- domain names. An attacker could possibly use this issue to cause a homograph attack. (CVE-2019-15237) It was discovered that Roundcube Webmail did not properly sanitize certain attributes when handling CSS within HTML messages and certain SVG attributes. An attacker could possibly use this issue to cause a cross-site scripting attack. (CVE-2024-38356, CVE-2024-38357) It was discovered that Roundcube Webmail did not properly sanitize certain HTML attributes when rendering e-mail messages. An attacker could possibly use this issue to cause a cross-site scripting attack. (CVE-2024-42008) It was discovered that Roundcube Webmail did not properly filter certain CSS token sequences within rendered e-mail messages. An attacker could possibly use this issue to obtain sensitive information. (CVE-2024-42010) It was discovered that Roundcube Webmail did not properly treat an SVG tag as an image source within its HTML sanitizer. An attacker could possibly use this issue to bypass remote image blocking to track email open actions or potentially bypass access control. (CVE-2026-25916) It was discovered that Roundcube Webmail did not properly handle comments within Cascading Style Sheets (CSS). An attacker could possibly use this issue to perform a CSS injection attack. (CVE-2026-26079) Update instructions: The problem can becorrected by updating your system to the following package versions: Ubuntu 24.04 LTS roundcube-core 1.6.6+dfsg-2ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS roundcube-core 1.5.0+dfsg.1-2ubuntu0.1~esm6 Available with Ubuntu Pro roundcube-plugins 1.5.0+dfsg.1-2ubuntu0.1~esm6 Available with Ubuntu Pro Ubuntu 20.04 LTS roundcube-core 1.4.3+dfsg.1-1ubuntu0.1~esm8 Available with Ubuntu Pro roundcube-plugins 1.4.3+dfsg.1-1ubuntu0.1~esm8 Available with Ubuntu Pro Ubuntu 18.04 LTS roundcube-core 1.3.6+dfsg.1-1ubuntu0.1~esm8 Available with Ubuntu Pro roundcube-plugins 1.3.6+dfsg.1-1ubuntu0.1~esm8 Available with Ubuntu Pro Ubuntu 16.04 LTS roundcube-core 1.2~beta+dfsg.1-0ubuntu1+esm8 Available with Ubuntu Pro roundcube-plugins 1.2~beta+dfsg.1-0ubuntu1+esm8 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8223-1 CVE-2019-15237, CVE-2024-38356, CVE-2024-38357, CVE-2024-42008, CVE-2024-42010, CVE-2026-25916, CVE-2026-26079 . Numerous issues fixed in Roundcube Webmail for multiple Ubuntu versions. Important updates recommended for security.. Roundcube Webmail, Ubuntu update, HTML sanitation, security fix. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in information disclosure, IMAP injection, CSRF bypass, bypass of remote image blocking, cross-site scripting, access control bypass, or privilege escalation.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6196-1
Several security issues were fixed in Roundcube Webmail.. ========================================================================== Ubuntu Security Notice USN-8132-1 March 30, 2026 roundcube vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Roundcube Webmail. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapack Details: It was discovered that Roundcube Webmail did not properly sanitize certain HTML elements within the e-mail body. An attacker could possibly use this issue to cause a cross-site scripting attack. This issue was only addressed in Ubuntu 16.04 LTS. (CVE-2016-4068, CVE-2016-4069) It was discovered that Roundcube Webmail did not properly handle certain configuration parameters. An attacker could possibly use this issue to execute arbitrary code. This issue was only addressed in Ubuntu 16.04 LTS. (CVE-2016-9920) It was discovered that Roundcube Webmail did not properly sanitize CSS styles within SVG documents. An attacker could possibly use this issue to cause a cross-site scripting attack. This issue was only addressed in Ubuntu 16.04 LTS. (CVE-2017-6820) It was discovered that Roundcube Webmail did not properly restrict exec call in certain drivers of the password plugin. An authenticated user could possibly use this issue to perform arbitrary password resets. This issue was only addressed in Ubuntu 16.04 LTS. (CVE-2017-8114) It was discovered that Roundcube Webmail did not properly set file permissions within the Enigma plugin. An attacker could possibly use this issue to exfiltrate GPG private keys via network connectivity. (CVE-2018-1000071) It was discovered that Roundcube Webmail did not properly handle GnuPG MDC integrity-protection warnings. An attacker could possibly use this issue to obtain sensitive information fromencrypted communications. (CVE-2018-19205) It was discovered that Roundcube Webmail did not properly sanitize and tags within HTML attachments. An attacker could possibly use this issue to cause a cross-site scripting attack. (CVE-2018-19206) It was discovered that Roundcube Webmail did not properly handle partially encrypted multipart messages. An attacker could possibly use this issue to cause leaking of the plaintext of encrypted messages via an email reply. (CVE-2019-10740) It was discovered that Roundcube Webmail did not properly sanitize a certain parameter within the archive plugin. An attacker could possibly use this issue to perform an IMAP injection attack. This issue was only addressed in Ubuntu 16.04 LTS. (CVE-2018-9846) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS roundcube-core 1.3.6+dfsg.1-1ubuntu0.1~esm7 Available with Ubuntu Pro roundcube-plugins 1.3.6+dfsg.1-1ubuntu0.1~esm7 Available with Ubuntu Pro Ubuntu 16.04 LTS roundcube-core 1.2~beta+dfsg.1-0ubuntu1+esm7 Available with Ubuntu Pro roundcube-plugins 1.2~beta+dfsg.1-0ubuntu1+esm7 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8132-1 CVE-2016-4068, CVE-2016-4069, CVE-2016-9920, CVE-2017-6820, CVE-2017-8114, CVE-2018-1000071, CVE-2018-19205, CVE-2018-19206, CVE-2018-9846, CVE-2019-10740 . Several security issues in Roundcube Webmail for Ubuntu fixed. Update advised for affected versions immediately.. Roundcube Webmail Security, Ubuntu Vulnerabilities, Cross-Site Scripting Threats, IMAP Injection Risks. . Severity: Important. LinuxSecurity.com Team
USN-8097-1 introduced a regression in roundcube. ========================================================================== Ubuntu Security Notice USN-8097-2 March 18, 2026 roundcube regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: USN-8097-1 introduced a regression in roundcube Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapack Details: USN-8097-1 fixed a vulnerability in roundcube. The update caused a regression affecting the HTML sanitizer, preventing Roundcube from rendering any email message body. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that Roundcube Webmail did not properly sanitize the animate tag within SVG documents. An attacker could possibly use this issue to cause a cross-site scripting attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS roundcube-core 1.4.3+dfsg.1-1ubuntu0.1~esm7 Available with Ubuntu Pro roundcube-plugins 1.4.3+dfsg.1-1ubuntu0.1~esm7 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8097-2 https://ubuntu.com/security/notices/USN-8097-1 https://launchpad.net/bugs/2144682 . Roundcube security fix in Ubuntu 20.04 LTS addresses regression affecting email rendering and XSS.. Roundcube Security Fix, Ubuntu 20.04 LTS, XSS Vulnerability, HTML Sanitization Issue. . Severity: Important. LinuxSecurity.com Team
Roundcube Webmail could be made to run arbitrary code via cross-site scripting.. ========================================================================== Ubuntu Security Notice USN-8097-1 March 16, 2026 roundcube vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Roundcube Webmail could be made to run arbitrary code via cross-site scripting. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapack Details: It was discovered that Roundcube Webmail did not properly sanitize the animate tag within SVG documents. An attacker could possibly use this issue to cause a cross-site scripting attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS roundcube-core 1.6.6+dfsg-2ubuntu0.1+esm2 Available with Ubuntu Pro Ubuntu 22.04 LTS roundcube-core 1.5.0+dfsg.1-2ubuntu0.1~esm5 Available with Ubuntu Pro Ubuntu 20.04 LTS roundcube-core 1.4.3+dfsg.1-1ubuntu0.1~esm6 Available with Ubuntu Pro roundcube-plugins 1.4.3+dfsg.1-1ubuntu0.1~esm6 Available with Ubuntu Pro Ubuntu 18.04 LTS roundcube-core 1.3.6+dfsg.1-1ubuntu0.1~esm6 Available with Ubuntu Pro roundcube-plugins 1.3.6+dfsg.1-1ubuntu0.1~esm6 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8097-1 CVE-2025-68461 . Roundcube Webmail security update for Ubuntu releases addresses cross-site scripting risks. Upgrade to mitigate risks..Roundcube Webmail, Ubuntu security, cross site scripting. . Severity: Important. LinuxSecurity.com Team
Vulnerabilities were discovered in Roundcube, a skinnable AJAX based webmail solution for IMAP servers, which might lead to information disclosure or privilege escalation. CVE-2026-25916 NULL CATHEDRAL discovered that the HTML sanitizer doesn't treat SVG. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4480-1
CERT Polska and nullcathedral discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not correctly process and sanitize requests. This would allow an attacker to perform CSS injection attacks, or leak sensitive information. For the oldstable distribution (bookworm), these problems have been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6137-1
Get the latest Linux and open source security news straight to your inbox.