www.securityweek.com 25 Sept 2026, 06:57 UTC

Hackers Exploit Roundcube SQL Flaw to Target Webmail Servers

Hackers Exploit Roundcube SQL Flaw to Target Webmail Servers
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

THREAT actors are exploiting a high-severity SQL injection vulnerability in Roundcube, the open-source webmail client, Canada’s Cyber Centre has warned. Tracked as CVE-2026-48842 and rated 8.1 by CVSS, the flaw affects the `virtuser_query` plugin and can be exploited without authentication. The plugin uses `preg_replace()` with backslash escaping to prevent injection, but specially crafted queries containing backslash sequences can bypass that protection. The resulting input can cause quote characters to be added to an SQL string sent to the database.

Roundcube fixed the vulnerability in versions 1.6.16 and 1.7.1, released in late May. The Cyber Centre said on [date unavailable] that open-source reporting indicates CVE-2026-48842 is being exploited in the wild, although it did not provide details about the attacks or confirm their scope.

Paymob information security lead Omar Ahmed said successful exploitation could allow attackers to manipulate database operations and potentially access protected information, user identities, messages and address books, as well as map authentication workflows and administrative functions. Shadowserver data identifies more than 500,000 internet-accessible Roundcube servers, but the number running vulnerable versions is unknown. Administrators should update affected installations to 1.6.16 or 1.7.1.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline