CVE-2026-35540 | Roundcube Webmail up to 1.6.13 HTML Mail Message resource transfer (Nessus ID 304879 / WID-SEC-2026-0789)
A vulnerability categorized as problematic has been discovered in Roundcube Webmail up to 1.6.13. This issue affects some unknown processing of the component HTML Mail Message Handler. The manipulation results in incorrect resource transfer.
This vulnerability is reported as CVE-2026-35540. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.