CVE-2026-35544 | Roundcube Webmail up to 1.5.13/1.6.13 HTML Mail Message resource transfer (Nessus ID 304893 / WID-SEC-2026-0789)
A vulnerability has been found in Roundcube Webmail up to 1.5.13/1.6.13 and classified as problematic. Affected is an unknown function of the component HTML Mail Message Handler. This manipulation causes incorrect resource transfer.
This vulnerability is tracked as CVE-2026-35544. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.