« Volver al listado

CVE-2026-35537

Estado: AnalizadaAlta (7.5)—

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CVE de deserialización insegura (CWE-502) en aplicación web expuesta (AV:N, PR:N). El vector CVSS señala acceso remoto sin autenticación. La ejecución de código se infiere de CWE-502 y 'arbitrary file write' que puede derivar en RCE, aunque el texto enfatiza escritura de archivos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-35537",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-35537",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-03T13:11:34.838938Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "Roundcube",
          "product": "Webmail",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.5.14",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.6.0",
              "lessThan": "1.6.14",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-03T04:17:10.313",
  "references": [
    {
      "url": "https://github.com/roundcube/roundcubemail/commit/618c5428edc69fb088e7ac6c89e506dd39df3",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/commit/6d586cfa4d8a31f7957f7a445aaedd52592a0e74",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/commit/a4ead994d2f0ea92e4a1603196a197e0d5df1620",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.5.14",
      "tags": [
        "Release Notes"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.6.14",
      "tags": [
        "Release Notes"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc5",
      "tags": [
        "Release Notes"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/04/11/6",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data."
    },
    {
      "lang": "es",
      "value": "Se descubrió un problema en Roundcube Webmail antes de las versiones 1.5.14 y 1.6.14. La deserialización insegura en el gestor de sesiones de redis/memcache puede conducir a operaciones de escritura de archivos arbitrarias por parte de atacantes no autenticados a través de datos de sesión manipulados."
    }
  ],
  "lastModified": "2026-07-24T21:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40F75FD7-CF6D-4DC4-A33D-625D0F02FAB3",
              "versionEndExcluding": "1.5.14"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF4B6448-D4F5-4680-B32C-9366630E9485",
              "versionEndExcluding": "1.6.14",
              "versionStartIncluding": "1.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}