🛡️ openSUSE-SU-2026:20586-1 — roundcubemail (CVE-2026-35537)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for roundcubemail

This update for roundcubemail fixes the following issues:

Changes in roundcubemail:

  • update to 1.6.15

This is a security update to the stable version 1.6 of Roundcube Webmail.

It provides fixes to some regressions introduced in the previous release

as well a recently reported security vulnerability:

SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm.

This version is considered stable and we recommend to update all productive

installations of Roundcube 1.6.x with it. Please do backup your data before updating!

+ Fix regression where mail search would fail on non-ascii search criteria (#10121)

+ Fix regression where some data url images could get ignored/lost (#10128)

+ Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke (bsc#1261157)

  • update to 1.6.14

This is a security update to the stable version 1.6 of Roundcube Webmail.

+ Fix Postgres connection using IPv6 address (#10104)

+ Security: Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler

(bsc#1261488, CVE-2026-35537)

+ Security: Fix bug where a password could get changed without providing the old password

+ Security: Fix IMAP Injection + CSRF bypass in mail search

+ Security: Fix remote image blocking bypass via various SVG animate attributes

+ Security: Fix remote image blocking bypass via a crafted body background attribute

+ Security: Fix fixed position mitigation bypass via use of !important

+ Security: Fix XSS issue in a HTML attachment preview

+ Security: Fix SSRF + Information Disclosure via stylesheet links to a local network hosts

Affected software

openSUSE-SU-2026:20586-1 is recorded against 1 package.

  • roundcubemail (fixed in 1.6.15-bp160.1.1)

Timeline and source

Published on 17 April 2026 and last revised on 22 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-04-17
Updated 2026-08-20
Modified 2026-04-22
Fix URL N/A

Affected Packages

Software From version Fixed in
roundcubemail 1.6.15-bp160.1.1

Similar Threats

Free Vulnerability Check

Is your site affected by openSUSE-SU-2026:20586-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:20586-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2026