CVE-2026-35543 identifies a vulnerability in Roundcube Webmail versions before 1.5.14 and 1.6.14, allowing an attacker to bypass the remote image blocking feature. This bypass is achieved by sending an email containing specific SVG content with animate attributes. Rated as a medium severity (CVSS 5.3), the vulnerability can be exploited remotely with low complexity and no user interaction, potentially leading to information disclosure or an access-control bypass. There is currently no evidence of active exploitation, nor are there any publicly available exploit modules or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.14CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 1.6.0, < 1.6.14CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 0, < 1.5.14CPE match | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.