https://seclists.org/oss-sec/2026/q2/100: CVE-2026-35537+moRoundcube arbitrary write + ID/XSS/etc. prior to 1.6.14
Published Apr 11, 2026
·Updated
Affected Software
1 affected component
Roundcube Roundcube<1.5.14, <1.6.14, =1.7-rc5
Frequently Asked Questions
1
What is the severity of CVE-2026-35537?
CVE-2026-35537 has been classified with a high severity due to its potential for pre-authentication arbitrary write and cross-site scripting vulnerabilities.
2
How do I fix CVE-2026-35537?
To fix CVE-2026-35537, upgrade to Roundcube versions 1.5.14, 1.6.14, or later releases as they include patches for this vulnerability.
3
What versions of Roundcube are affected by CVE-2026-35537?
CVE-2026-35537 affects Roundcube versions prior to 1.5.14, 1.6.14, and all pre-releases of version 1.7.
4
Is CVE-2026-35537 an authentication vulnerability?
CVE-2026-35537 is primarily an arbitrary write vulnerability that can be exploited without authentication.
5
What types of attacks can be executed due to CVE-2026-35537?
CVE-2026-35537 allows for arbitrary writing of files and potential cross-site scripting attacks.