Roundcube Webmail 0-Click Stored XSS (CVE-2026-54432, CVE-2026-54433) — Versions Prior to 1.6.17 / 1.7.2 — Threadlinqs Intelligence
As of 2026-07-10, Roundcube Webmail 0-Click Stored XSS (CVE-2026-54432, CVE-2026-54433) — Versions Prior to 1.6.17 / 1.7.2 is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1185 · Severity: HIGH · Status: ACTIVE · Category: VULNERABILITY
Roundcube Webmail versions prior to 1.6.17 and 1.7.2 contain two zero-click stored XSS vulnerabilities: CVE-2026-54432 executes arbitrary JavaScript via an unescaped attachment MIME type on the
On 2026-07-05 the Roundcube project released security updates 1.6.17 and 1.7.2 patching six issues, two of which are zero-click stored cross-site scripting vulnerabilities reported by Bohdan Kurinnoy of Samsung R&D Institute Ukraine (SRUKR). CVE-2026-54432 stems from the attachment-validation warning page failing to escape the MIME type string associated with an uploaded/received attachment; because Roundcube renders this warning automatically when a message containing a suspicious or blocked attachment type is opened, an attacker who controls the MIME type field of a crafted attachment can inject and execute arbitrary JavaScript in the victim's webmail session the moment the warning page loads — no click, download, or explicit user action required beyond viewing the message. GitHub release notes for 1.6.17 describe the fix as making the attachment-validation warning page properly escape MIME type data (tracked upstream alongside issue #10193 for an unrelated TNEF fix in the same release). CVE-2026-54433 is a stored XSS in Roundcube's plain-text message rendering engine: content that should be rendered as inert text is instead interpreted and executed as script when the recipient views the message in plain-text mode, a mode users often trust as inherently safe from HTML-borne script injection, which defeats the visual/behavioral cues (e.g., 'blocked images' or 'view as HTML' prompts) users rely on to spot suspicious mail. Because Roundcube is server-rendered webmail, any script executing in the DOM runs in the authenticated session origin and can read the DOM, issue XHR/fetch requests using the victim's session cookie, exfiltrate mail contents, or, per community discussion of the disclosure, exfiltrate the session token itself to enable full account/mailbox takeover. Both CVEs were disclosed and patched simultaneously alongside four other Roundcube 1.6.17/1.7.2 fixes, per the vendor's own release notes and changelog: (1) an infinite loop in the TNEF (winmail.dat) decoder enabling a denial-of-service via malformed attachments (GitHub issue #10193, reported by stafra); (2) password-plugin vulnerabilities involving session-injected usernames (reported by Glendaenri and peppersghost); (3) two additional SSRF bypass cases exploitable via local-address URL formats (reported by Leenear); and (4) a denial-of-service via crafted compressed-RTF size values inside TNEF attachments (reported by h0rk1p). The same 1.6.17 release also shipped two unrelated feature additions (Enigma automatic public-key lookup via HKP v1, tracked as #5314, and Enigma Kolab WOAT support, #8626) that are not security-relevant to this threat. As of this research, NVD has not yet published CVSS scores for CVE-2026-54432/CVE-2026-54433 (empty NVD API results at time of analysis, confirmed via direct NVD REST query on 2026-07-10); no public PoC exploit code or confirmed in-the-wild exploitation has been identified for these two specific CVEs — CERT-FR's advisory (CERTFR-2026-AVI-0835) catalogs the same release's issues as a mix of security-bypass, DoS, SSRF, and XSS-via-indirect-code-injection categories without assigning independent severity beyond referencing the vendor bulletin. This is not Roundcube's first appearance on CISA's Known Exploited Vulnerabilities (KEV) catalog: in February 2026, CISA added two earlier, unrelated Roundcube flaws — CVE-2025-49113 (CVSS 9.9, deserialization-of-untrusted-data remote code execution for authenticated users, patched June 2025) and CVE-2025-68461 (CVSS 7.2, SVG-animate-tag cross-site scripting, patched December 2025) — to the KEV catalog after confirming active exploitation, with a federal remediation deadline of 2026-03-13. Neither CVE-2026-54432 nor CVE-2026-54433 currently appears in the KEV catalog, but the vendor's recurring cadence of XSS/RCE/SSRF findings and its history of rapid weaponization after disclosure (the CVE-2025-49113 RCE was reportedly weaponized within 48 hours of disclosure per prior reporting) elevat
Weaknesses (CWE)
CWE-79, CWE-116
Target sectors: technology, hosting-providers, government administration, education, small-and-medium-business, any-sector-running-self-hosted-webmail
Target regions: Global
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-54432, CVE-2026-54433, T1566, T1189, T1204, T1059, T1505, T1211, T1539, T1550, T1213, T1114