PT-2026-29983 · Unknown+1 · Roundcube Webmail+1

Nullcathedral1

·

Published

2026-03-18

·

Updated

2026-05-07

·

CVE-2026-35544

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Roundcube Webmail versions prior to 1.5.14 and prior to 1.6.14
Description A flaw exists in Roundcube Webmail that stems from inadequate sanitization of Cascading Style Sheets (CSS) within HTML email messages. This can allow for a bypass of existing mitigations through the use of the '!important' declaration in CSS.
Recommendations Update Roundcube Webmail to version 1.5.14 or later. Update Roundcube Webmail to version 1.6.14 or later.

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-06326
CVE-2026-35544
GHSA-XPQH-GRPW-4XMG

Affected Products

Red Os
Roundcube Webmail