Loading
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.
Use CWE-843, Roundcube vendor hub and Webmail product page to widen CVE-2026-35541 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-49113, CVE-2025-68461 and CVE-2025-68460 for nearby disclosures in the same product family.