CVE-2026-9818 | Roundcube Local/Private URL Fetch Bypass

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: 2026-05-28 Last update: 2026-05-28 Assigner: 6064c9f1-42e5-4cc5-a67a-1636d7a9d3fd Source: 6064c9f1-42e5-4cc5-a67a-1636d7a9d3fd

Conclusion & alert: This CVE is rejected; it is not tracked as an active vulnerability. Mandatory action: Do not treat as an active exposure for patching queues—follow the CVE record status and authoritative vendor or program statements only.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2026-9818

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

EPSS has not published a score for this CVE yet—common while NVD analysis or FIRST scoring is still pending. Monitor daily updates and reassess once scores appear.

Common vulnerability scoring system (CVSS) metrics for CVE-2026-9818

CVSS metrics for this CVE.

No CVSS data in dataset for this CVE.

Weakness enumeration for CVE-2026-9818

GitHub Security Advisory for CVE-2026-9818

GHSA-mhgj-jxxf-gxj9 · Severity: medium — Roundcube's HTML sanitization path for message rendering allows loopback, localhost, RFC1918,...

Affected software / configurations for CVE-2026-9818

Vendor Product Version Raw CPE
No affected products in dataset.

References for CVE-2026-9818

URL Tags
No references in dataset.
cvelogic Threat Intelligence