Junglewise Threat Intelligence

CVE-2026-35544: Roundcube Webmail CSS sanitization bypass in HTML email

CVE-2026-35544 · Severity: medium · CVSS 5.3 · Published 2026-04-03

Technologies: roundcube/roundcubemail (Packagist), Roundcube Webmail. Vendors: Packagist, Roundcube.

Executive brief

Roundcube Webmail, a widely used open-source email client, contains a security flaw in how it handles the styling of incoming HTML emails. An attacker can send a specially crafted email that uses specific CSS commands to bypass security filters intended to keep email content contained. This could allow an attacker to manipulate the visual layout of the webmail interface, potentially leading to UI redressing or other integrity-related issues for the user viewing the message.

Technical details

A vulnerability exists in Roundcube Webmail's HTML email rendering engine due to insufficient sanitization of Cascading Style Sheets (CSS). Specifically, the application fails to properly restrict the use of the '!important' declaration within CSS styles. An unauthenticated remote attacker can exploit this by sending a crafted HTML email that leverages '!important' to bypass existing mitigations designed to prevent 'fixed-position' elements from overlaying the webmail UI. This is classified as an Incorrect Resource Transfer Between Spheres (CWE-669). The issue is resolved in versions 1.5.14, 1.6.14, and 1.7-rc5.

Affected products

  • Roundcube Webmail < 1.5.14, 1.6.x < 1.6.14

Timeline

  • 2026-03-18: patched: Security updates released for 1.5, 1.6, and 1.7 branches
  • 2026-04-03: disclosed: Initial CVE publication

References

Related threats