Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Summary

A pre-authentication SQL injection vulnerability in the Roundcube Webmail virtuser_query plugin, identified as CVE-2026-48842, is being actively exploited in the wild. The Canadian Centre for Cyber Security has issued a warning about this flaw, which affects versions prior to 1.6.16 and 1.7.1. The vulnerability is due to an issue with the preg_replace() function.

IFF Assessment

FOE

The discovery and active exploitation of a critical vulnerability in a widely used webmail client pose a significant threat to users and organizations, enabling attackers to compromise systems.

Severity

8.1 High

Defender Context

Defenders need to ensure their Roundcube Webmail installations are updated to the patched versions to mitigate the risk of this actively exploited SQL injection vulnerability. Organizations should monitor for any signs of compromise related to this CVE and review their web application security practices.

Read Full Story →