Roundcube Webmail flaw CVE-2026-48842 lets attackers access all tenants' mail data
A pre-authentication SQL injection vulnerability, CVE-2026-48842, was discovered in the Roundcube Webmail virtuser_query plugin, affecting versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The flaw allows attackers to bypass input filtering using crafted backslash sequences, executing malicious SQL queries without any credentials or user interaction. On shared hosting environments, where a single database account serves multiple tenants, the vulnerability can expose email records, invoices, and sensitive correspondence belonging to all users on the platform. The Canadian Centre for Cyber Security confirmed the vulnerability has been exploited in the wild, and it carries a CVSS score of 8.1. Roundcube released patches on 24 May 2026, and administrators are urged to upgrade immediately, restrict database privileges, and disable virtuser_query where virtual user mapping is not needed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in