Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-48844

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published May 25, 2026
Vendor unknown

Description

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

References