CVE-2026-35541 Details
Description
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.
A type confusion vulnerability has been identified in the password plugin of Roundcube Webmail, affecting versions prior to 1.5.14 and 1.6.14. The vulnerability arises from incorrect password comparison, which can lead to a situation where a password is changed without requiring the old password. This issue is caused by loose comparison operations that allow for type juggling, creating a potential security risk.
Users can update to Roundcube Webmail versions 1.5.14, 1.6.14, or 1.7-rc5, all of which include the necessary fix. Instructions for updating are available on the Roundcube website and GitHub release pages.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| roundcube webmail | < 1.5.14 >= 1.6.0, < 1.6.14 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | Initial Analysis | [email protected] |
| Apr 3, 2026 | New CVE Received | [email protected] |