CVE-2026-48849

MEDIUM

Roundcube Webmail - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-48849. PoCs published by AnandJogawade.

AI-analyzed exploit summary The repository contains a technical writeup and proof-of-concept images demonstrating a stored XSS vulnerability in Roundcube Webmail (CVE-2026-48849). The README and images provide details on how the vulnerability can be exploited, but no functional exploit code is included.

Description

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

Exploits (2)

github WRITEUP
by AnandJogawade · poc
https://github.com/AnandJogawade/CVE-2026-48849-Roundcube-Webmail-Stored-XSS

The repository contains a technical writeup and proof-of-concept images demonstrating a stored XSS vulnerability in Roundcube Webmail (CVE-2026-48849). The README and images provide details on how the vulnerability can be exploited, but no functional exploit code is included.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Roundcube Webmail
Auth required
Prerequisites: Access to Roundcube Webmail instance · Valid user credentials
devstral-2 · analyzed Jun 15, 2026 Full analysis →
nomisec WRITEUP
by AnandJogawade · poc
https://github.com/AnandJogawade/CVE-2026-48849---Stored-XSS-HTML-Injection-CSS-Injection-in-Roundcube-Webmail

The repository contains a technical writeup and proof-of-concept screenshots demonstrating a stored XSS vulnerability in Roundcube Webmail (CVE-2026-48849). The README and images detail the exploit steps but do not include executable code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Roundcube Webmail
Auth required
Prerequisites: Access to Roundcube Webmail instance · Valid user credentials
devstral-2 · analyzed Jun 15, 2026 Full analysis →

Scores

CVSS v3 4.4
EPSS 0.0019
EPSS Percentile 9.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
Roundcube/Webmail 1.6.0 - 1.6.16
Roundcube/Webmail 1.7.0 - 1.7.1
Published May 25, 2026
Tracked Since May 26, 2026