CVE-2026-35538

LOW

Roundcube Webmail < 1.5.14 - CSRF

Title source: rule

Description

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

Scores

CVSS v3 3.1
EPSS 0.0004
EPSS Percentile 12.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-88
Status published
Products (4)
roundcube/roundcubemail 1.7-beta - 1.7-rc5Packagist
Roundcube/Webmail < 1.5.14
roundcube/webmail < 1.5.14
Roundcube/Webmail 1.6.0 - 1.6.14
Published Apr 03, 2026
Tracked Since Apr 03, 2026