SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-54433

HIGH · CVSS 7.2 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Roundcube Webmail versions prior to 1.6.17 and 1.7.x before 1.7.2 are vulnerable to stored Cross-Site Scripting (XSS) through specially crafted plain-text email messages, allowing attackers to execute malicious JavaScript within the victim's authenticated session without any user interaction. This high-severity vulnerability poses significant risks to users, as it can lead to session hijacking and data theft. Organizations using affected versions should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-54433
Severity
HIGH
CVSS
7.2
EPSS
0.31%
Java

Original NVD Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

Related CVEs

Other vulnerabilities affecting the same vendor(s)