CVE-2026-35537 identifies an unsafe deserialization vulnerability in Roundcube Webmail versions before 1.5.14 and 1.6.14, specifically within its redis/memcache session handler. This flaw enables unauthenticated attackers to achieve arbitrary file write operations by submitting crafted session data. Although the CVSS score is low (3.7) due to high attack complexity, the ability to write arbitrary files poses a notable integrity risk. There is no evidence of active exploitation or public exploit code, but the CVE has been placed on a "Hot List" for active monitoring.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.14CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 1.6.0, < 1.6.14CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 0, < 1.5.14CPE match | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.