Type Confusion Vulnerability in Roundcube Webmail by Roundcube
CVE-2026-35541

4.2MEDIUM

Key Information:

Vendor

Roundcube

Status
Vendor
CVE Published:
3 April 2026

What is CVE-2026-35541?

A security issue has been identified in Roundcube Webmail prior to versions 1.5.14 and 1.6.14. The flaw resides in the password plugin, where incorrect password comparison logic may result in type confusion. This vulnerability permits an attacker to change a user's password without knowledge of the existing password, potentially compromising user accounts and sensitive information.

Affected Version(s)

Webmail 0 < 1.5.14

Webmail 1.6.0 < 1.6.14

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.