Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6196-1 | roundcube security update |
Github GHSA |
GHSA-46pv-mj2g-93gh | Roundcube Webmail: Incorrect password comparison in the password plugin |
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Password Change Without Old Password via Type Confusion in Roundcube Password Plugin |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* |
Fri, 03 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Password Change Without Old Password via Type Confusion in Roundcube Password Plugin | |
| First Time appeared |
Roundcube
Roundcube webmail |
|
| Vendors & Products |
Roundcube
Roundcube webmail |
Fri, 03 Apr 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. | |
| Weaknesses | CWE-843 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-03T12:52:08.638Z
Reserved: 2026-04-03T03:50:46.901Z
Link: CVE-2026-35541
Updated: 2026-04-03T12:52:05.290Z
Status : Analyzed
Published: 2026-04-03T05:16:22.283
Modified: 2026-04-07T20:45:56.447
Link: CVE-2026-35541
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:54:22Z
Debian DSA
Github GHSA