
CVE-2026-35542 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY … https://www.cve.org/CVERecord?id=CVE-2026-35542
Post summary
Roundcube Webmail versions before 1.5.14 and 1.6.14 have a vulnerability where the remote image blocking can be bypassed by injecting a crafted background attribute in a BODY tag.
