CVE-2026-35545

Published Apr 3, 2026

Last updated 19 days ago

Overview

Description
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.
Source
cve@mitre.org
NVD status
Analyzed
Products
webmail

Risk scores

CVSS 3.1

Type
Primary
Base score
8.2
Impact score
4.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Severity
HIGH

Weaknesses

cve@mitre.org
CWE-669

Social media

Hype score
Not currently trending

Configurations