Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Release 1.7.2 Add HEAD request handler to the static.php Fix so the oauth_password_claim claim is retrieved via token or userinfo request (#9631) Fix bug where static.php would return a 416 error on a specific Range request. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-517daa8d64 2026-07-16 01:19:18.912120+00:00 -------------------------------------------------------------------------------- Name : roundcubemail Product : Fedora 44 Version : 1.7.2 Release : 1.fc44 URL : http://www.roundcube.net Summary : Round Cube Webmail is a browser-based multilingual IMAP client Description : RoundCube Webmail is a browser-based multilingual IMAP client with an application-like user interface. It provides full functionality you expect from an e-mail client, including MIME support, address book, folder manipulation, message searching and spell checking. RoundCube Webmail is written in PHP and requires a database: MySQL, PostgreSQL and SQLite are known to work. The user interface is fully skinnable using XHTML and CSS 2. -------------------------------------------------------------------------------- Update Information: Release 1.7.2 Add HEAD request handler to the static.php Fix so the oauth_password_claim claim is retrieved via token or userinfo request (#9631) Fix bug where static.php would return a 416 error on a specific Range request (#10194) Fix bug where configured skin logo wasn't loaded via static.php resulting in 404 error (#10191) Fix bug where installto.sh would fail if public_html folder does not exist in the target directory (#10202) Revert "Prefer 8bit over quoted-printable for HTML parts, when force_7bit is disabled (#8477)" (#10198) Fix incorrect unfolding of folded lines when importing vCard 2.1 contacts (#9647) Fix bug where Imagick could leave large temporary files on failure (#10230) Fix bug where redis/memcache session could have been updated more oftenthan needed Fix support for untyped tokens in OIDC backchannel logout, require unset nonce (#10097) Security: Fix an infinite loop in TNEF (winmail.dat) decoder (#10193) Security: Fix various vulnerabilities in the password plugin using session- injected username Security: Fix stored XSS via unescaped attachment MIME type on the attachment- validation warning page [CVE-2026-54432] Security: Fix SSRF bypass via specific local address URLs - two new cases Security: Fix zero-click stored XSS in plain-text rendering [CVE-2026-54433] Security: Fix DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 6 2026 Remi Collet - 1.7.2-1 - update to 1.7.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500063 - CVE-2026-54433 roundcubemail: Roundcube Webmail: Arbitrary code execution via zero-click cross-site scripting [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500063 [ 2 ] Bug #2500065 - CVE-2026-62642 roundcubemail: Roundcube Webmail: Denial of Service via infinite loop in TNEF decoder [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500065 [ 3 ] Bug #2500067 - CVE-2026-62644 roundcubemail: Roundcube Webmail: Account takeover via username spoofing in password plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500067 [ 4 ] Bug #2500068 - CVE-2026-54432 roundcubemail: Roundcube Webmail: Stored Cross-Site Scripting via unescaped attachment MIME type [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500068 [ 5 ] Bug #2500071 - CVE-2026-62641 roundcubemail: Roundcube Webmail: Denial of Service via crafted TNEF compressed-RTF size [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500071 [ 6 ] Bug #2500072 - CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500072 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-517daa8d64' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Roundcube Webmail could be made to run programs as your login if it opened a malicious website.. ========================================================================== Ubuntu Security Notice USN-8482-1 June 30, 2026 roundcube vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS Summary: Roundcube Webmail could be made to run programs as your login if it opened a malicious website. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapack Details: It was discovered that Roundcube Webmail was prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. An attacker could use this issue to execute arbitrary web script in the context of an affected user's session. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS roundcube 1.6.11+dfsg-1ubuntu0.26.04.1~esm1 Available with Ubuntu Pro roundcube-core 1.6.11+dfsg-1ubuntu0.26.04.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8482-1 CVE-2025-68461 . Roundcube Webmail has a Cross-Site Scripting issue that could allow attackers to execute scripts via malicious websites. Update now.. Roundcube Webmail, Ubuntu security, XSS vulnerability, web application security, system update. . Severity: Important. LinuxSecurity.com Team
. Debian LTS Advisory DLA-4657-1
Version 1.6.15 This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to some regressions introduced in the previous release as well a recently reported security vulnerability: SVG Animate FUNCIRI Attribute Bypass \u2014 Remote Image Loading via. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8ba1a085a9 2026-04-09 03:21:08.450860+00:00 -------------------------------------------------------------------------------- Name : roundcubemail Product : Fedora 43 Version : 1.6.15 Release : 1.fc43 URL : https://roundcube.net/ Summary : Round Cube Webmail is a browser-based multilingual IMAP client Description : RoundCube Webmail is a browser-based multilingual IMAP client with an application-like user interface. It provides full functionality you expect from an e-mail client, including MIME support, address book, folder manipulation, message searching and spell checking. RoundCube Webmail is written in PHP and requires a database: MySQL, PostgreSQL and SQLite are known to work. The user interface is fully skinnable using XHTML and CSS 2. -------------------------------------------------------------------------------- Update Information: Version 1.6.15 This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to some regressions introduced in the previous release as well a recently reported security vulnerability: SVG Animate FUNCIRI Attribute Bypass \u2014 Remote Image Loading via fill/filter/stroke, reported by class_nzm. This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating! CHANGELOG Fix regression where mail search would fail on non-ascii search criteria (#10121) Fix regression where some data url images could get ignored/lost (#10128) Fix SVG Animate FUNCIRI Attribute Bypass \u2014 Remote Image Loadingvia fill/filter/stroke -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 30 2026 Remi Collet - 1.6.15-1 - update to 1.6.15 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2454784 - CVE-2026-35543 roundcubemail: Roundcube Webmail: Information disclosure and access-control bypass via animated SVG in email [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454784 [ 2 ] Bug #2454786 - CVE-2026-35545 roundcubemail: Roundcube Webmail: Information disclosure and access-control bypass via SVG content in email. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454786 [ 3 ] Bug #2454793 - CVE-2026-35538 CVE-2026-35539 CVE-2026-35540 CVE-2026-35541 CVE-2026-35542 CVE-2026-35544 roundcubemail: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454793 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8ba1a085a9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Stay secure by updating to Roundcube Webmail 1.6.15 with fixes for SVG vulnerabilities. Protect your email data now.. Roundcube Webmail, security update, Fedora 43, remote image loading, information disclosure. . Severity: Important. LinuxSecurity.com Team
Roundcube Webmail could be made to expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-7636-1 July 14, 2025 roundcube vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Roundcube Webmail could be made to expose sensitive information over the network. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers Details: It was discovered that Roundcube Webmail incorrectly handled sanitization in the message_body function. A remote attacker could possibly use this issue to send and receive emails as another user. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS roundcube 1.6.6+dfsg-2ubuntu0.1+esm1 Available with Ubuntu Pro roundcube-core 1.6.6+dfsg-2ubuntu0.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7636-1 CVE-2024-42009 . Roundcube Webmail for Ubuntu 24.04 LTS leaks confidential information through the network. Urgent updates suggested.. Roundcube Webmail, Ubuntu security, information disclosure. . Severity: Important. LinuxSecurity.com Team
Roundcube Webmail could allow remote code execution.. ========================================================================== Ubuntu Security Notice USN-7584-1 June 19, 2025 roundcube vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Roundcube Webmail could allow remote code execution. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers Details: It was discovered that Roundcube Webmail did not properly sanitize the _from parameter in a URL, leading to PHP Object Deserialization. A remote attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 roundcube 1.6.10+dfsg-1ubuntu0.1 roundcube-core 1.6.10+dfsg-1ubuntu0.1 Ubuntu 24.10 roundcube 1.6.8+dfsg-2ubuntu0.1 roundcube-core 1.6.8+dfsg-2ubuntu0.1 Ubuntu 24.04 LTS roundcube 1.6.6+dfsg-2ubuntu0.1 roundcube-core 1.6.6+dfsg-2ubuntu0.1 Ubuntu 22.04 LTS roundcube 1.5.0+dfsg.1-2ubuntu0.1~esm4 Available with Ubuntu Pro roundcube-core 1.5.0+dfsg.1-2ubuntu0.1~esm4 Available with Ubuntu Pro roundcube-plugins 1.5.0+dfsg.1-2ubuntu0.1~esm4 Available with Ubuntu Pro Ubuntu 20.04 LTS roundcube 1.4.3+dfsg.1-1ubuntu0.1~esm5 Available with Ubuntu Pro roundcube-core 1.4.3+dfsg.1-1ubuntu0.1~esm5 Available with Ubuntu Pro roundcube-plugins 1.4.3+dfsg.1-1ubuntu0.1~esm5 Available with Ubuntu Pro Ubuntu 18.04 LTS roundcube 1.3.6+dfsg.1-1ubuntu0.1~esm5 Available with Ubuntu Pro roundcube-core 1.3.6+dfsg.1-1ubuntu0.1~esm5 Available with Ubuntu Pro roundcube-plugins 1.3.6+dfsg.1-1ubuntu0.1~esm5 Available with Ubuntu Pro Ubuntu 16.04 LTS roundcube 1.2~beta+dfsg.1-0ubuntu1+esm6 Available with Ubuntu Pro roundcube-core 1.2~beta+dfsg.1-0ubuntu1+esm6 Available with Ubuntu Pro roundcube-plugins 1.2~beta+dfsg.1-0ubuntu1+esm6 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7584-1 CVE-2025-49113 Package Information: https://launchpad.net/ubuntu/+source/roundcube/1.6.10+dfsg-1ubuntu0.1 https://launchpad.net/ubuntu/+source/roundcube/1.6.8+dfsg-2ubuntu0.1 https://launchpad.net/ubuntu/+source/roundcube/1.6.6+dfsg-2ubuntu0.1 . Notice of Ubuntu Security USN-7584-1 highlights a vulnerability in Roundcube that could lead to remote code execution across various Ubuntu releases.. Roundcube Security, Ubuntu Roundcube Update, Remote Code Execution Ubuntu. . Severity: Critical. LinuxSecurity.com Team
This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities: Fix Post-Auth RCE via PHP Object Deserialization reported by firs0v. This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a5f56fe8ff 2025-06-11 03:51:24.306039+00:00 -------------------------------------------------------------------------------- Name : roundcubemail Product : Fedora 41 Version : 1.6.11 Release : 1.fc41 URL : https://roundcube.net/ Summary : Round Cube Webmail is a browser-based multilingual IMAP client Description : RoundCube Webmail is a browser-based multilingual IMAP client with an application-like user interface. It provides full functionality you expect from an e-mail client, including MIME support, address book, folder manipulation, message searching and spell checking. RoundCube Webmail is written in PHP and requires a database: MySQL, PostgreSQL and SQLite are known to work. The user interface is fully skinnable using XHTML and CSS 2. -------------------------------------------------------------------------------- Update Information: This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities: Fix Post-Auth RCE via PHP Object Deserialization reported by firs0v. This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating! CHANGELOG Managesieve: Fix match-type selector (remove unsupported options) in delete header action (#9610) Improve installer to fix confusion about disabling SMTP authentication (#9801) Fix PHP warning in index.php (#9813) OAuth: Fix/improve token refresh Fix dark modebug where wrong colors were used for blockquotes in HTML mail preview (#9820) Fix HTML message preview if it contains floating tables (#9804) Fix removing/expiring redis/memcache records when using a key prefix Fix bug where a wrong SPECIAL-USE folder could have been detected, if there were more than one per-type (#9781) Fix a default value and documentation of password_ldap_encodage option (#9658) Remove mobile/floating Create button from the list in Settings > Folders (#9661) Fix Delete and Empty buttons state while creating a folder (#9047) Fix connecting to LDAP using ldapi:// URI (#8990) Fix cursor position on "below the quote" reply in HTML mode (#8700) Fix bug where attachments with content type of application/vnd.ms-tnef were not parsed (#7119) -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 2 2025 Remi Collet - 1.6.11-1 - update to 1.6.11 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369708 - CVE-2025-49113 roundcubemail: From CVEorg collector [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2369708 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a5f56fe8ff' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Kirill Firsov discovered that Roundcube, a skinnable AJAX based webmail solution for IMAP servers, was performing PHP Object deserialization on unvalidated input, which could lead to remote code execution by an authenticated attacker. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4211-1
Get the latest Linux and open source security news straight to your inbox.