CVE-2026-35538

unknown
Published 2026-04-03 · Modified 2026-04-04
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v2
VIR risk

Description

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-35538

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.6.5+dfsg-1+deb12u8
debian debianbullseyefixed1.4.15+dfsg.1-1+deb11u8
debian debiansidfixed1.6.14+dfsg-1
debian debiantrixiefixed1.6.15+dfsg-0+deb13u1

Package impact

EcosystemPackageVulnerableFixed
php Packagistroundcube/roundcubemail>=1.7-beta,<1.7-rc51.7-rc5

References

Verify integrity in audit chain (admin only). AS-IS.