Fedora 44 : roundcubemail (2026-2aa96a9ce5)

medium Nessus Plugin ID 338391

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 44 host has a package installed that is affected by multiple vulnerabilities as referenced in the FEDORA-2026-2aa96a9ce5 advisory.

## Release 1.7.3

- OAuth: Don't log an error when a refreshed token's TTL is below refresh_interval (#10213)
- Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
- Fix bug where searching in example_addressbook plugin was reporting zero results despite matches (#9022)
- Fix vCard import mis-detecting folded continuation lines as BEGIN/END:VCARD (#9593)
- Fix bug where the php session driver practically disabled session.lazy_write optimization (#9885, #10248)
- Fix bug where dates could get displayed shifted back one day in some places (#9403)
- Fix regression where it wasn't possible to hide a skin logo image anymore (#10254)
- Fix decoding of multi-segment RFC2231 extended attachment filenames (#10268)
- Fix vCard import silently dropping properties with a non-item group prefix (#10271)
- Fix so `REQUEST_URI` is used as a fallback if `PATH_INFO` is empty in static.php (#10181)
- Security: Add basic validation for content proxied by the css proxy
- Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
- Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
- Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
- Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the `search_filter`
- Security: Fix arbitrary Sieve script injection via a filter rule name bypassing `managesieve_disabled_actions`
- Security: Fix RCE via `cmd_learn` driver of markasjunk plugin
- Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
- Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
- Security: Fix stored XSS in Add to address book action
- Security: Fix HTML/CSS sanitization bypass via SVG animate `by` attribute



Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected roundcubemail package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2026-2aa96a9ce5

Plugin Details

Severity: Medium

ID: 338391

File Name: fedora_2026-2aa96a9ce5.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/20/2026

Updated: 8/20/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.71

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-59882

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:44, p-cpe:/a:fedoraproject:fedora:roundcubemail

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/11/2026

Vulnerability Publication Date: 6/11/2026

Reference Information

CVE: CVE-2026-48998, CVE-2026-49214, CVE-2026-55568, CVE-2026-55766, CVE-2026-55767, CVE-2026-59882