Information Disclosure Vulnerability in Roundcube Webmail
CVE-2026-35543

5.3MEDIUM

Key Information:

Vendor

Roundcube

Status
Vendor
CVE Published:
3 April 2026

What is CVE-2026-35543?

An issue in Roundcube Webmail allows remote image blocking to be bypassed through the use of SVG content with animate attributes in email messages. This vulnerability could potentially lead to unauthorized information exposure or access-control breaches, compromising user privacy and data integrity. It is crucial to update to the latest versions to mitigate these risks.

Affected Version(s)

Webmail 0 < 1.5.14

Webmail 1.6.0 < 1.6.14

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.