Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unvalidated CSS Proxy Response Causing XSS and Information Disclosure in Roundcube Webmail |
Mon, 17 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing. | |
| First Time appeared |
Roundcube
Roundcube webmail |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roundcube
Roundcube webmail |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-17T12:40:29.903Z
Reserved: 2026-08-17T12:40:29.556Z
Link: CVE-2026-74998
No data.
Status : Received
Published: 2026-08-17T13:16:54.270
Modified: 2026-08-17T13:16:54.270
Link: CVE-2026-74998
No data.
OpenCVE Enrichment
Updated: 2026-08-17T15:00:08Z