ZeroHour

CVE-2026-35538

CVSS 3.1
3.1 low
EPSS
<1%p27
Published
()
Modified
Description

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

Vendors
roundcube
Products
webmail
Weakness
CWE-88
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.