---
cve: "CVE-2026-48844"
severity: "HIGH"
cvss: 7.5
epss: "41%"
vendor: "Roundcube"
kev: false
exploited: false
published: "2026-05-25 20:16:36"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T03:49:59+02:00"
---

# CVE-2026-48844

> 7.5 HIGH · 🧪 PoC

## Beschreibung

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- ea1798a6fbf060abcc0ba73b2435036bf8016a5a (Commit)
- d40ec266240f2456a52c24ef2848e18bbfb5c300 (Commit)

## Referenzen

- <https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1>
- <https://github.com/roundcube/roundcubemail/releases/tag/1.7.1>
- <https://github.com/roundcube/roundcubemail/commit/6a777d7394b763ce9acfce86c1a521e14a02d862>
- <https://github.com/roundcube/roundcubemail/releases/tag/1.6.16>
- <https://github.com/roundcube/roundcubemail/commit/ea1798a6fbf060abcc0ba73b2435036bf8016a5a>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-48844) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
