PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35545 Roundcube CVE debrief

CVE-2026-35545 is a vulnerability in Roundcube Webmail that allows remote image blocking to be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Affected users should apply patches to prevent potential information disclosure or access-control bypass.

Vendor
Roundcube
Product
Webmail
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Users of Roundcube Webmail versions before 1.5.15 and 1.6.15 should apply patches to prevent potential information disclosure or access-control bypass. This vulnerability may impact operators, platforms, vulnerability-management teams, and security teams.

Technical summary

The remote image blocking feature in Roundcube Webmail can be bypassed via SVG content in an e-mail message. This involves the animate element with attributeName=fill/filter/stroke. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. This issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. Affected users should apply patches to prevent potential information disclosure or access-control bypass. The vulnerability may impact operators, platforms, vulnerability-management teams, and security teams. Users of Roundcube Webmail versions before 1.5.15 and 1.6.15 should apply patches to prevent potential information disclosure or access-control bypass.

Defensive priority

Apply patches to prevent potential information disclosure or access-control bypass.

Recommended defensive actions

  • Apply patches to Roundcube Webmail versions before 1.5.15 and 1.6.15
  • Restrict access to sensitive areas of the webmail interface
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-04-03T05:16:22.980Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. This vulnerability affects Roundcube Webmail versions before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message, potentially leading to information disclosure or access-control bypass.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T05:16:22.980Z and has not been modified since then. The NVD entry is currently Analyzed.