CVE-2026-35541 identifies a type confusion vulnerability in Roundcube Webmail versions before 1.5.14 and 1.6.14, where incorrect password comparison in the password plugin allows an attacker to change a user's password without knowing the old one. This vulnerability carries a medium CVSS score of 4.2, characterized by a network attack vector, high attack complexity, and requiring low privileges, with low impact on confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.14CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 1.6.0, < 1.6.14CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 0, < 1.5.14CPE match | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.