CVE-2026-35543

unknown
Published 2026-04-03 · Modified 2026-04-04
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2
VIR risk

Description

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-35543

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.6.5+dfsg-1+deb12u8
debian debianbullseyefixed1.4.15+dfsg.1-1+deb11u8
debian debiansidfixed1.6.14+dfsg-1
debian debiantrixiefixed1.6.15+dfsg-0+deb13u1

Package impact

EcosystemPackageVulnerableFixed
php Packagistroundcube/roundcubemail>=1.7-beta,<1.7-rc51.7-rc5

References

Verify integrity in audit chain (admin only). AS-IS.