https://seclists.org/oss-sec/2026/q2/101: CVE-2026-35537+moRoundcube arbitrary write + ID/XSS/etc. prior to 1.6.14
Published Apr 11, 2026
·Updated
Affected Software
1 affected component
Roundcube Roundcube<1.6.14, =1.5.14, =1.6.14
Frequently Asked Questions
1
What is the severity of CVE-2026-35537?
CVE-2026-35537 has been classified as a high severity vulnerability due to its potential for arbitrary write access and its associated risks.
2
How do I fix CVE-2026-35537?
To fix CVE-2026-35537, upgrade Roundcube to version 1.6.15 or later, which addresses this vulnerability.
3
What types of attacks can be executed due to CVE-2026-35537?
CVE-2026-35537 can lead to arbitrary write vulnerabilities, cross-site scripting (XSS), and other exploitation risks.
4
Which versions of Roundcube are affected by CVE-2026-35537?
CVE-2026-35537 affects Roundcube versions prior to 1.6.15, specifically 1.5.14 and 1.6.14.
5
Is there a patch available for CVE-2026-35537?
Yes, patches for CVE-2026-35537 are included in Roundcube versions 1.5.15 and 1.6.15, released on March 29, 2026.