CVE-2026-35545 | Roundcube Webmail up to 1.5.14/1.6.14 SVG Content resource transfer (Nessus ID 304900 / WID-SEC-2026-0789)
A vulnerability was found in Roundcube Webmail up to 1.5.14/1.6.14 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SVG Content Handler. Such manipulation leads to incorrect resource transfer.
This vulnerability is listed as CVE-2026-35545. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.