Executive brief
Roundcube Webmail, a popular open-source web-based email client, contains a security flaw in its mail search functionality. An attacker could exploit this to bypass security protections (CSRF) or manipulate email server commands. This could allow an unauthorized user to perform actions on behalf of a legitimate user or interfere with mail processing operations.
Technical details
A vulnerability exists in Roundcube Webmail's mail search component (program/actions/mail/search.php) due to improper neutralization of argument delimiters (CWE-88). Specifically, unsanitized IMAP SEARCH command arguments allow for IMAP injection. This flaw can also be leveraged to achieve a CSRF bypass during mail search operations. The attack requires network access and low-level authentication (PR:L), with a high complexity (AC:H) for successful exploitation. The issue is resolved in versions 1.5.14, 1.6.14, and 1.7-rc5.
Affected products
- Roundcube Webmail < 1.5.14, 1.6.x < 1.6.14, 1.7-rc < 1.7-rc5
Timeline
- 2026-03-18: patched: Security updates released for 1.5, 1.6, and 1.7 branches.
- 2026-04-03: disclosed: CVE-2026-35538 published.
References
- https://github.com/roundcube/roundcubemail/commit/5fe8a69956a9683a4269f3ad2a68e18deebf8a15
- https://github.com/roundcube/roundcubemail/commit/7daf5aa9c190ccc75bb31672d8fee9938877fd64
- https://github.com/roundcube/roundcubemail/commit/b18a8fa8e81571914c0ff55d4e20edb459c6952c
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.14
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.14
- https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc5
- https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14