Vulnerability
Published 2026-05-24
Verified 2026-09-27

Roundcube Webmail CVE-2026-48842 (CVSS 8.1): pre-auth SQLi in virtuser_query — exploited in the wild (CCCS AV26-503)

Roundcube security updates 1.6.16 / 1.7.1 (published 24 May 2026) fix CVE-2026-48842: pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass (reporter: skull). Affects Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 when the plugin is enabled/reachable. CVE.report CVSS 3.1 8.1 HIGH (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Same releases also fix XSS/CSS injection, SSRF/local URL fetch bypasses, remote-image CSS var() bypass, pre-auth arbitrary file delete via redis/memcache session poisoning, and LDAP autovalues code-evaluation removal. Canadian Centre for Cyber Security advisory AV26-503 (updated 21 September 2026; amplified SecurityWeek / The Hacker News 25 Sep) confirms open-source reporting of active exploitation — CCCS did not publish attack details. UPDATE 25–26 Sep desk: SentinelOne describes the SQLi path (backslash sequences defeating preg_replace escaping so quotes land in the SQL string); Shadowserver Foundation telemetry cited by THN shows >523,000 internet-exposed Roundcube instances with 10 hosts flagged vulnerable as of 23 September 2026. Primary: Roundcube 24 May security news + GitHub 1.6.16; wire: SecurityWeek 25 Sep / THN 25 Sep.

Product
Roundcube Webmail (virtuser_query plugin)
Versions
1.6.x before 1.6.16; 1.7.x before 1.7.1 (plugin must be enabled for SQLi path)
CVSS
(CVSS 3.1 HIGH, CVE.report / CNA)
Exploited in Australia?
unknown
Patch to
Upgrade to Roundcube 1.6.16 or 1.7.1 (or later security trains); confirm virtuser_query plugin state; priority for internet-facing webmail; review web/DB/auth logs for pre-auth SQLi probes; backup before upgrade per vendor

Primary: Roundcube — security updates 1.6.16 and 1.7.1 (24 May 2026) · Vendor: GitHub — Roundcube Webmail 1.6.16 release notes (also 1.7.1) · CVE: CVE-2026-48842 · SecurityWeek — Roundcube CVE-2026-48842 in attackers’ crosshairs / CCCS (25 Sep 2026)

vulnerabilities australia cloud identity