Cross-Site Scripting Vulnerability in Roundcube Webmail Product
CVE-2026-35539

6.1MEDIUM

Key Information:

Vendor

Roundcube

Status
Vendor
CVE Published:
3 April 2026

What is CVE-2026-35539?

A vulnerability in Roundcube Webmail prior to versions 1.5.14 and 1.6.14 allows attackers to execute arbitrary JavaScript via insufficient HTML sanitization of text/html attachments in preview mode. When users preview these attachments, malicious scripts can execute, potentially compromising user data and session integrity.

Affected Version(s)

Webmail 0 < 1.5.14

Webmail 1.6.0 < 1.6.14

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.