HIGH
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14
Published Apr 3, 2026
7.5
HIGHCVSS 3.1
EPSS 0.60%
Description
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
Affected products
-
- Version 0StatusaffectedConstraints<1.5.14
- Version 1.6.0StatusaffectedConstraints<1.6.14
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://www.openwall.com/lists/oss-security/2026/04/11/6 Issue TrackingMailing List
- https://github.com/advisories/GHSA-rxj3-rrwm-pj4r Advisory
- https://github.com/roundcube/roundcubemail/commit/618c5428edc69fb088e7ac6c89e506dd39df3 Patch
- https://github.com/roundcube/roundcubemail/commit/6d586cfa4d8a31f7957f7a445aaedd52592a0e74 Patch
- https://github.com/roundcube/roundcubemail/commit/a4ead994d2f0ea92e4a1603196a197e0d5df1620 Patch
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.14 Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.14 Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc5 Release Notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-35537
- https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14 Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 3, 2026
Updated Apr 11, 2026
Reserved Apr 3, 2026
Link CVE-2026-35537
CISA Vulnrichment
GHSA-RXJ3-RRWM-PJ4R Updated Apr 3, 2026