CVE-2026-35538
Roundcube Webmail: Unsanitized IMAP SEARCH command arguments
3.1
LOW
CVSS 3.1
EPSS 0.01%
Description
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
How to fix CVE-2026-35538
To remediate CVE-2026-35538, upgrade the affected package to a fixed version below.
- Debian/roundcube—upgrade to 1.4.15+dfsg.1-1+deb11u8 or later
- —upgrade to 1.7-rc5 or later
Is CVE-2026-35538 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.4.15+dfsg.1-1+deb11u8
- >= 1.7-beta, < 1.7-rc5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.1 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |