Skip to content
Ubuntu 26.04 LTS Roundcube Important XSS Risk USN-8482

Ubuntu 26.04 LTS Roundcube Important XSS Risk USN-8482

Linuxsecurity •LinuxSecurity Advisories • June 30, 2026

Roundcube Webmail could be made to run programs as your login if it opened a malicious website. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapack Details: It was discovered that Roundcube Webmail was prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. An attacker could use this issue to execute arbitrary web script in the context of an affected user's session.

Roundcube Webmail could be made to run programs as your login if it opened

Software Description:

- roundcube: skinnable AJAX based webmail solution for IMAP servers - metapack

It was discovered that Roundcube Webmail was prone to a Cross-Site-Scripting

(XSS) vulnerability via the animate tag in an SVG document. An attacker

could use this issue to execute arbitrary web script in the context of an

affected user's session.

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS roundcube 1.6.11+dfsg-1ubuntu0.26.04.1~esm1 Available with Ubuntu Pro roundcube-core 1.6.11+dfsg-1ubuntu0.26.04.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

Ubuntu Security Notice USN-8482-1

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

Companies (1)

Platforms (1)

Vulnerabilities (1)