Attackers cash in on an unauthenticated Roundcube mail flaw

Canada's cyber centre says a patched SQL injection in Roundcube Webmail is being exploited in the wild.

CSBadmin
2 Min Read

Roundcube administrators who never applied May’s update should move now. Canada’s Centre for Cyber Security says attackers are exploiting the bug it fixed, tracked as CVE-2026-48842, which scores 8.1 on the CVSS scale.

The bug is a pre-authentication SQL injection in the virtuser_query plugin, which maps an email address to a mailbox username. The plugin relies on a preg_replace() filter to escape dangerous input. Crafted queries containing backslash sequences slip past that escaping, letting an attacker place quote characters into a database query with no login required.

SentinelOne, which analyzed the flaw, said a successful hit can expose mail account credentials and stored messages. A Paymob security lead added that attackers could also tamper with database operations, read address books, and map admin functions.

Roundcube shipped fixes in 1.6.16 and 1.7.1. The Cyber Centre gave no details of the ongoing exploitation, citing open-source reporting only.

The Shadowserver Foundation’s scan turns up more than 523,000 internet-facing Roundcube installations. Confirmed vulnerable hosts are far fewer, but the sprawling footprint keeps the target pool large.

The platform has drawn repeated attention. In July, Proofpoint linked a suspected China-aligned group to attacks on Roundcube using the VShell post-exploitation tool. Earlier flaws, CVE-2025-49113 and CVE-2025-68461, were added to CISA’s exploited-vulnerabilities catalog this year. Administrators still running the older branches should treat the patch as overdue.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.