CVE-2026-35541 | Roundcube Webmail up to 1.5.13/1.6.13 Password Plugin type confusion (Nessus ID 304902 / WID-SEC-2026-0789)
A vulnerability identified as problematic has been detected in Roundcube Webmail up to 1.5.13/1.6.13. Impacted is an unknown function of the component Password Plugin. This manipulation causes type confusion.
This vulnerability appears as CVE-2026-35541. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.