Junglewise Threat Intelligence

CVE-2026-35538: Roundcube Webmail IMAP injection in mail search

CVE-2026-35538 · Severity: low · CVSS 3.1 · Published 2026-04-03

Technologies: roundcube/roundcubemail (Packagist), Roundcube Webmail. Vendors: Packagist, Roundcube.

Executive brief

Roundcube Webmail, a popular open-source web-based email client, contains a security flaw in its mail search functionality. An attacker could exploit this to bypass security protections (CSRF) or manipulate email server commands. This could allow an unauthorized user to perform actions on behalf of a legitimate user or interfere with mail processing operations.

Technical details

A vulnerability exists in Roundcube Webmail's mail search component (program/actions/mail/search.php) due to improper neutralization of argument delimiters (CWE-88). Specifically, unsanitized IMAP SEARCH command arguments allow for IMAP injection. This flaw can also be leveraged to achieve a CSRF bypass during mail search operations. The attack requires network access and low-level authentication (PR:L), with a high complexity (AC:H) for successful exploitation. The issue is resolved in versions 1.5.14, 1.6.14, and 1.7-rc5.

Affected products

  • Roundcube Webmail < 1.5.14, 1.6.x < 1.6.14, 1.7-rc < 1.7-rc5

Timeline

  • 2026-03-18: patched: Security updates released for 1.5, 1.6, and 1.7 branches.
  • 2026-04-03: disclosed: CVE-2026-35538 published.

References

Related threats