PT-2026-29977 · Roundcube · Webmail

Published

2026-04-03

·

Updated

2026-04-03

·

CVE-2026-35538

CVSS v3.1

3.1

Low

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2026-35538

Affected Products

Webmail