ROUNDCUBE Webmail flaw CVE-2026-48842, rated 8.1 by CVSS, is being exploited in the wild, according to an advisory updated by the Canadian Centre for Cyber Security on 21 September 2026. Roundcube fixed the issue on 24 May, but unpatched internet-facing servers remain at risk. The vulnerability affects 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, specifically when the `virtuser_query` plugin is present.
The flaw is a pre-authentication SQL injection vulnerability, meaning an attacker does not need an account or user interaction. The plugin uses PHP’s `preg_replace()` and backslash escaping when processing email addresses for database lookups. Specially crafted backslash sequences can bypass that protection and inject SQL into the backend database. Depending on permissions and configuration, successful exploitation could expose mailbox credentials, stored messages and other information. The report cites open-source reporting and SentinelOne’s assessment, but says there are no confirmed indicators that reliably identify attacks.
Administrators should check their Roundcube versions, install the updates and disable `virtuser_query` if it is not required; disabling it should not replace patching. Organisations should also review application logs for unusual backslashes, quotes or SQL commands, while recognising that updating alone cannot reveal whether a prior compromise occurred.