CVE-2026-35545 identifies a remote image blocking bypass vulnerability affecting Roundcube Webmail versions before 1.5.15 and 1.6.15. This flaw permits an attacker to circumvent the image blocking feature via SVG content, specifically the 'animate' element, embedded in an email. With a CVSSv3.1 score of 5.3 (Medium), the vulnerability presents a network-based attack vector with low complexity, potentially leading to information disclosure or access-control bypass. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.15CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 1.6.0, < 1.6.15CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 0, < 1.5.15CPE match | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.