PT-2026-29983 · Unknown+1 · Roundcube Webmail+1

·

CVE-2026-35544

·

Published

2026-03-18

·

Updated

2026-05-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Roundcube Webmail versions prior to 1.5.14 and prior to 1.6.14
Description A flaw exists in Roundcube Webmail that stems from inadequate sanitization of Cascading Style Sheets (CSS) within HTML email messages. This can allow for a bypass of existing mitigations through the use of the '!important' declaration in CSS.
Recommendations Update Roundcube Webmail to version 1.5.14 or later. Update Roundcube Webmail to version 1.6.14 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06326
CVE-2026-35544
GHSA-XPQH-GRPW-4XMG

Affected Products

Red Os
Roundcube Webmail