
CVE-2026-35538 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during ma… https://www.cve.org/CVERecord?id=CVE-2026-35538
Post summary
The CVE refers to unsanitized IMAP SEARCH arguments in Roundcube Webmail that could result in IMAP injection or CSRF bypass, with no mention of a patch or active exploitation.
