CVE-2026-35543 | Roundcube Webmail up to 1.5.13/1.6.13 SVG Content resource transfer (Nessus ID 304887 / WID-SEC-2026-0789)
A vulnerability, which was classified as problematic, was found in Roundcube Webmail up to 1.5.13/1.6.13. This impacts an unknown function of the component SVG Content Handler. The manipulation results in incorrect resource transfer.
This vulnerability is identified as CVE-2026-35543. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.