CVE-2026-48842
Roundcube Webmail SQL Injection
Description
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
INFO
Published Date :
May 25, 2026, 8:16 p.m.
Last Modified :
Sept. 25, 2026, 4:17 a.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | HIGH | 8254265b-2729-46b6-b9e3-3dfca2d5bfca | ||||
| CVSS 3.1 | HIGH | MITRE-CVE | ||||
| CVSS 3.1 | HIGH | [email protected] |
Solution
- Update Roundcube Webmail to version 1.6.16 or later.
- Update Roundcube Webmail to version 1.7.1 or later.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-48842.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-48842 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-48842
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-48842 vulnerability anywhere in the article.
-
security.nl
Roundcube Webmail SQL Injection-lek misbruikt bij aanvallen
Een SQL Injection-kwetsbaarheid in Roundcube wordt misbruikt bij aanvallen. Dat laat het Canadese Centrum voor Cybersecurity weten. Roundcube is opensource-webmailsoftware en wordt door allerlei organ ... Read more
-
The Hacker News
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS scor ... Read more
The following table lists the changes that have been made to the
CVE-2026-48842 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by [email protected]
Sep. 25, 2026
Action Type Old Value New Value Added Reference https://github.com/roundcube/roundcubemail/commit/3406183a9976e36f992d3468f37d0e2346526ee9 Added Reference https://github.com/roundcube/roundcubemail/commit/87124cc7136a48b5fa9d2b40dfead6e9dcaeaf4b Added Reference https://github.com/roundcube/roundcubemail/releases/tag/1.6.16 Added Reference https://github.com/roundcube/roundcubemail/releases/tag/1.7.1 Added Reference https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1 Removed Reference https://github.com/roundcube/roundcubemail/commit/3406183a9976e36f992d3468f37d0e2346526ee9 Removed Reference https://github.com/roundcube/roundcubemail/commit/87124cc7136a48b5fa9d2b40dfead6e9dcaeaf4b Removed Reference https://github.com/roundcube/roundcubemail/releases/tag/1.6.16 Removed Reference https://github.com/roundcube/roundcubemail/releases/tag/1.7.1 Removed Reference https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1 -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Sep. 25, 2026
Action Type Old Value New Value Added Reference http://www.openwall.com/lists/oss-security/2026/06/03/17 Removed Reference http://www.openwall.com/lists/oss-security/2026/06/03/17 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Sep. 25, 2026
Action Type Old Value New Value Removed SSVC {'id': 'CVE-2026-48842', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-26T12:58:31.395155Z'} Added SSVC {'id': 'CVE-2026-48842', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-09-24T00:00:00+00:00'} -
CVE Translated by [email protected]
Jul. 24, 2026
Action Type Old Value New Value Added Translation Title: Webmail de Roundcube, Description: Roundcube Webmail 1.6.x anterior a 1.6.16 y 1.7.x anterior a 1.7.1 tiene una inyección SQL de preautenticación en el plugin virtuser_query mediante un bypass de escape de barra invertida de preg_replace(). -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-48842', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-26T12:58:31.395155Z'} -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'Roundcube', 'product': 'Webmail', 'versions': [{'status': 'affected', 'version': '1.6.0', 'lessThan': '1.6.16', 'versionType': 'semver'}, {'status': 'affected', 'version': '1.7.0', 'lessThan': '1.7.1', 'versionType': 'semver'}], 'defaultStatus': 'unaffected'}] -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Jun. 03, 2026
Action Type Old Value New Value Added Reference http://www.openwall.com/lists/oss-security/2026/06/03/17 -
New CVE Received by [email protected]
May. 25, 2026
Action Type Old Value New Value Added Description Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. Added CVSS V3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Added CWE CWE-89 Added Reference https://github.com/roundcube/roundcubemail/commit/3406183a9976e36f992d3468f37d0e2346526ee9 Added Reference https://github.com/roundcube/roundcubemail/commit/87124cc7136a48b5fa9d2b40dfead6e9dcaeaf4b Added Reference https://github.com/roundcube/roundcubemail/releases/tag/1.6.16 Added Reference https://github.com/roundcube/roundcubemail/releases/tag/1.7.1 Added Reference https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1