CVE-2026-35538

LOW

Roundcube Webmail < 1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - IMAP Injection via Search Command Arguments

Title source: llm
STIX 2.1

Description

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

Scores

CVSS v3 3.1
EPSS 0.0028
EPSS Percentile 19.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-88
Status published
Products (4)
roundcube/roundcubemail 1.7-beta - 1.7-rc5Packagist
Roundcube/Webmail < 1.5.14
roundcube/webmail < 1.5.14
Roundcube/Webmail 1.6.0 - 1.6.14
Published Apr 03, 2026
Tracked Since Apr 03, 2026