CVE-2026-35539 | Roundcube Webmail up to 1.5.13/1.6.13 HTML Attachment HTML injection (Nessus ID 304892 / WID-SEC-2026-0789)
A vulnerability was found in Roundcube Webmail up to 1.5.13/1.6.13. It has been rated as problematic. This vulnerability affects unknown code of the component HTML Attachment Handler. The manipulation leads to HTML injection.
This vulnerability is documented as CVE-2026-35539. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.