PatchSiren cyber security CVE debrief
CVE-2026-35545 Roundcube CVE debrief
CVE-2026-35545 is a vulnerability in Roundcube Webmail that allows remote image blocking to be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Affected users should apply patches to prevent potential information disclosure or access-control bypass.
- Vendor
- Roundcube
- Product
- Webmail
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Users of Roundcube Webmail versions before 1.5.15 and 1.6.15 should apply patches to prevent potential information disclosure or access-control bypass. This vulnerability may impact operators, platforms, vulnerability-management teams, and security teams.
Technical summary
The remote image blocking feature in Roundcube Webmail can be bypassed via SVG content in an e-mail message. This involves the animate element with attributeName=fill/filter/stroke. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. This issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. Affected users should apply patches to prevent potential information disclosure or access-control bypass. The vulnerability may impact operators, platforms, vulnerability-management teams, and security teams. Users of Roundcube Webmail versions before 1.5.15 and 1.6.15 should apply patches to prevent potential information disclosure or access-control bypass.
Defensive priority
Apply patches to prevent potential information disclosure or access-control bypass.
Recommended defensive actions
- Apply patches to Roundcube Webmail versions before 1.5.15 and 1.6.15
- Restrict access to sensitive areas of the webmail interface
- Monitor for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-03T05:16:22.980Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. This vulnerability affects Roundcube Webmail versions before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message, potentially leading to information disclosure or access-control bypass.
Official resources
-
CVE-2026-35545 CVE record
CVE.org
-
CVE-2026-35545 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Release Notes
-
Mitigation or vendor reference
[email protected] - Release Notes
-
Mitigation or vendor reference
[email protected] - Release Notes
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T05:16:22.980Z and has not been modified since then. The NVD entry is currently Analyzed.