Debian dla-4760 : roundcube - security update

critical Nessus Plugin ID 341564

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 11 / 12 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-4760 advisory.

------------------------------------------------------------------------- Debian LTS Advisory DLA-4760-1 [email protected] https://www.debian.org/lts/security/ Guilhem Moulin August 29, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : roundcube Version : 1.4.15+dfsg.1-1+deb11u11 1.6.5+dfsg-1+deb12u11 CVE ID : CVE-2026-74997 CVE-2026-74998 CVE-2026-74999 CVE-2026-75000 CVE-2026-75002 CVE-2026-75003 CVE-2026-75004 CVE-2026-75006 CVE-2026-75007 CVE-2026-75010 Debian Bug : 1144059

Multiple vulnerabilities were discovered in Roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in cross-site scripting, server-side request forgery, information disclosure, privilege escalation, IMAP injection, account takeover, or remote code execution.

CVE-2026-74997

A remote code execution vulnerability was found in the cmd_learn learning driver of the markasjunk plugin. Placeholders such as %u (username), %l (localpart) and %d (domainpart) were injected with insufficiently sanitized/escaped values used within a `sh -c ''` shell construction, thereby allowing remote code execution from the user used to run roundcube (by default www-data).

Only installations where 1/ the markasjunk plugin was enabled, and 2/ where the `$config['markasjunk_learning_driver']` setting was set to `cmd_learn`, were affected by this vulnerability. In particular, stock installations were not affected since the plugin is not enabled by default.

CVE-2026-74998

Content proxied by the CSS proxy (which is used to retrieve remote style sheets linked to in text/html emails) was found to be lacking basic validation, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.

CVE-2026-74999

Paulos Yibelo discovered that the Add to address book action was subject to stored XSS due to insufficient sanitization of error messages and information popups.

CVE-2026-75000

Insufficient HTML/CSS sanitization may lead to remote image blocking bypass or XSS via crafted SVG animate `by` attribute sent in malicious text/html emails.

CVE-2026-75002

Zach Hanley discovered that mail search and RFC2088 IMAP4 LITERAL+ byte-count desynchronization may lead to IMAP command injection.

CVE-2026-75003

Milan Hoppe discovered that insufficient HTML/CSS sanitization may lead to remote image blocking bypass or XSS via unclosed url() in a FuncIRI attribute.

CVE-2026-75004

Milan Hoppe discovered that managesieve rule names were not sanitized, thereby allowing arbitrary sieve injection and bypass of the managesieve_disabled_actions restriction set by an administrator.

This vulnerability only affects installations where the managesieve plugin is enabled. In particular, stock installations were not affected since the plugin is not enabled by default.

CVE-2026-75006

Dmytro Ivanenko and Milan Hoppe discovered that that the CSS sanitization fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643 were insufficient, allowing a malicious embedded stylesheet in a text/html email to lead to SSRF or information disclosure.

CVE-2026-75007

Milan Hoppe discovered that the LDAP integration was subject to filter injection via unescaped %u/%fu/%d substitution.

CVE-2026-75010

The modoba driver of the password plugin was found to be leaking an authentication token, which may lead to account takeover.

Only installations where 1/ the password plugin was enabled, and 2/ where the `$config['password_driver']` setting was set to `modoboa`, were affected by this vulnerability. In particular, stock installations were not affected since the password plugin is not enabled by default.

For Debian 11 bullseye, these problems have been fixed in version 1.4.15+dfsg.1-1+deb11u11.

For Debian 12 bookworm, these problems have been fixed in version 1.6.5+dfsg-1+deb12u11.

We recommend that you upgrade your roundcube packages.

For the detailed security status of roundcube please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/roundcube

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Attachment:
signature.asc Description: PGP signature

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the roundcube packages.

See Also

https://packages.debian.org/source/bookworm/roundcube

https://packages.debian.org/source/bullseye/roundcube

https://security-tracker.debian.org/tracker/CVE-2026-35540

https://security-tracker.debian.org/tracker/CVE-2026-48843

https://security-tracker.debian.org/tracker/CVE-2026-62643

https://security-tracker.debian.org/tracker/CVE-2026-74997

https://security-tracker.debian.org/tracker/CVE-2026-74998

https://security-tracker.debian.org/tracker/CVE-2026-74999

https://security-tracker.debian.org/tracker/CVE-2026-75000

https://security-tracker.debian.org/tracker/CVE-2026-75002

https://security-tracker.debian.org/tracker/CVE-2026-75003

https://security-tracker.debian.org/tracker/CVE-2026-75004

https://security-tracker.debian.org/tracker/CVE-2026-75006

https://security-tracker.debian.org/tracker/CVE-2026-75007

https://security-tracker.debian.org/tracker/CVE-2026-75010

https://security-tracker.debian.org/tracker/source-package/roundcube

Plugin Details

Severity: Critical

ID: 341564

File Name: debian_DLA-4760.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/29/2026

Updated: 8/29/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.14

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-62643

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:11.0, cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:roundcube-core, p-cpe:/a:debian:debian_linux:roundcube-mysql, p-cpe:/a:debian:debian_linux:roundcube-pgsql, p-cpe:/a:debian:debian_linux:roundcube-plugins, p-cpe:/a:debian:debian_linux:roundcube-sqlite3, p-cpe:/a:debian:debian_linux:roundcube

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 8/29/2026

Vulnerability Publication Date: 3/31/2026

Reference Information

CVE: CVE-2026-35540, CVE-2026-48843, CVE-2026-62643, CVE-2026-74997, CVE-2026-74998, CVE-2026-74999, CVE-2026-75000, CVE-2026-75002, CVE-2026-75003, CVE-2026-75004, CVE-2026-75006, CVE-2026-75007, CVE-2026-75010

IAVA: 2026-A-0301-S, 2026-A-0521, 2026-A-0663