Roundcube Webmail Flaw CVE-2026-48842 Actively Exploited; Patches Released
A high-severity pre-authentication SQL injection vulnerability, CVE-2026-48842, has been identified in Roundcube Webmail's virtuser_query plugin, with active exploitation reported by the Canadian Centre for Cyber Security. The flaw carries a CVSS v3.1 score of 8.1 and allows unauthenticated attackers to inject malicious SQL by sending crafted HTTP requests to unpatched instances. The extent of damage depends on database contents and privileges, though OS command execution and full email theft have not been publicly confirmed. Roundcube has released patched versions 1.6.16 and 1.7.1 to address the issue across supported branches. Administrators are advised to update immediately, disable virtuser_query if unused, minimize database privileges, and avoid relying solely on web application firewalls as a substitute for patching.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in