CVE-2026-35543
—CVSS 3.1
5.3 medium
EPSS
<1%p34
Published
()
Modified
Description
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.
- Vendors
- roundcube
- Products
- webmail
- Weakness
- CWE-669
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.