Back
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
SiTech AI Team2 წთ. საკითხავი

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Canada's cyber security centre says CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail's virtuser_query plugin, is being exploited in the wild. Patches shipped in May 2026.

A patched SQL injection flaw in Roundcube Webmail is being actively exploited in the wild, Canada's cyber security centre warned this week, citing open-source reporting.

A pre-authentication SQL injection

The vulnerability is tracked as CVE-2026-48842 and carries a CVSS score of 8.1. It is a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail, affecting 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1.

The issue stems from a preg_replace() backslash escape bypass that allows attackers to inject arbitrary SQL statements without authenticating first.

What the flaw exposes

SentinelOne described the impact: "Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages."

Roundcube is widely deployed as a webmail front end, so a successful injection reaches the database sitting behind an organisation's mail service.

Patches and exposure

Roundcube released fixes in May 2026 as part of versions 1.6.16 and 1.7.1. Data from the Shadowserver Foundation shows more than 523,000 Roundcube instances exposed to the internet, with 10 of them flagged as vulnerable hosts as of September 23, 2026.

A familiar target

Roundcube has repeatedly drawn attackers hunting email. In July 2026, Proofpoint said it identified a suspected China-aligned adversary it calls UNK_MassTraction exploiting known Roundcube flaws to drop web shells or a post-exploitation tool named VShell. In February 2026, two other Roundcube vulnerabilities, CVE-2025-49113 and CVE-2025-68461, were listed by CISA as exploited in the wild. The Cyber Centre's update did not include further details about the ongoing exploitation activity.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.