PT-2026-29978 · Roundcube+1 · Roundcube Webmail+1

Y0Us

·

Published

2026-03-18

·

Updated

2026-05-07

·

CVE-2026-35539

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Roundcube Webmail versions prior to 1.5.14 and prior to 1.6.14
Description A flaw exists in Roundcube Webmail that allows for cross-site scripting (XSS). This occurs due to inadequate sanitization of HTML attachments when previewed. An attacker can exploit this by having a victim preview a specially crafted text/html attachment.
Recommendations Update Roundcube Webmail to version 1.5.14 or later. Update Roundcube Webmail to version 1.6.14 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-06179
CVE-2026-35539
GHSA-X4Q5-8J5G-HPJC

Affected Products

Red Os
Roundcube Webmail