MEDIUMVulnerability

CVE-2026-75000

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

Properties

severity
MEDIUM
score
5.8
epss_score
0.00323
cve_id
CVE-2026-75000
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
published_at
2026-08-17T13:16:54.580
last_modified
2026-09-01T21:04:08.583
epss_percentile
0.24817

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Incorrect Resource Transfer Between Spheres

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75000 — Ninja Signal Threat Intelligence | Ninja Signal