CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Roundcube Webmail HTML sanitisation bypass via SVG document permitting CSS injection; patched in 1.6.16 LTS / 1.7.1

cve · CVE-2026-48848

Coverage
1
first 2026-05-28 → last 2026-09-25
Latest activity
2026-09-25
CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, education, telco · regions: europe
Sources cited
5
5 hosts

Action items (1)

Do-now tasks recorded on the entries about CVE-2026-48848, newest first. Check the date before acting on an older one.

Defender insights

What each entry about CVE-2026-48848 tells a defender to do, newest first.

2026-05-28HIGHexploitedCVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)

Triage

Story timeline

  1. 2026-05-28CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
    trending-vulnerabilities
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-05-28/cve-2026-48842-roundcube-webmail-pre-authentication-sql-inje · ATT&CK page ↗

Entries about Roundcube Webmail HTML sanitisation bypass via SVG document permitting CSS injection; patched in 1.6.16 LTS / 1.7.1 (1)

2026-05-28 · view entry permalink →

HIGHCVE-2026-48842 +3exploitedupdatedNATOA2

CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)

The Roundcube Project shipped 1.6.16 (LTS) and 1.7.1 on 2026-05-24 patching a pre-authentication SQL-injection in the virtuser_query plugin: an unauthenticated network attacker can inject arbitrary SQL through the plugin's login-time virtual-user lookup when the plugin is enabled (Roundcube Project, 2026-05-24; NCSC Switzerland, 2026-05-27; Heise Security, 2026-05-27). Companion fixes in the same release: CVE-2026-48844 (HIGH, code injection in the LDAP autovalues option when configured; PHP-eval-class flaw), CVE-2026-48843 (HIGH; CSS-sanitisation bypass in HTML email via SVG animate attributeName="style" that can leak data through SSRF or disclose server-side information), and CVE-2026-48848 (HIGH, HTML-sanitisation bypass permitting CSS injection via a crafted SVG document). Branches 1.5.x and earlier are EOL and do not receive patches. Roundcube is the dominant self-hosted webmail across European public administrations, ISPs and academia, NCSC Switzerland flagged the cluster as requiring prompt action.

Roundcube webmail has a documented history of exploitation against government email systems specifically: the Winter Vivern (TA473) actor's CVE-2023-5631 cross-site-scripting zero-day targeted European government entities, and APT28 separately chained three earlier Roundcube flaws (CVE-2020-35730, CVE-2020-12641, CVE-2021-44026) to breach Ukrainian government email systems (BleepingComputer, 2026-09-24). Roundcube also ships pre-installed with the cPanel hosting-control panel (BleepingComputer, 2026-09-24), widening exposure beyond single-tenant installs to any organization whose mail runs on a cPanel-based hosting provider.

Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild.

Canadian Centre for Cyber Security 2026-09-21

Current exploitation status: Actively exploited

NCSC Switzerland post 12596

Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction.

BleepingComputer 2026-09-24
Updaterun 2026-09-25T0404Z-intelcvestagsactionstechniquesclassificationevidenceentitiesaffected_productssourcesbody

Canada's Cyber Centre updated its advisory on 2026-09-21 to record that "open-source reporting indicates that CVE-2026-48842 is being exploited in the wild" (Canadian Centre for Cyber Security, 2026-09-21), four months after the May patch. NCSC Switzerland updated its own Cyber Security Hub advisory to match on 2026-09-24, recording "Current exploitation status: Actively exploited" and citing the Canadian update as its source (NCSC Switzerland, 2026-09-24). Threat-monitoring nonprofit Shadowserver tracks more than 523,000 internet-exposed Roundcube instances, with no public breakdown of how many remain unpatched (BleepingComputer, 2026-09-24). Where immediate patching is not possible, disabling or removing the virtuser_query plugin removes the vulnerable code path entirely; the plugin is opt-in and mainly used by hosting/ISP-style deployments rather than single-tenant installs.

vulnerability28 May 05:00Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • bleepingcomputer.com1 (20%)
  • cyber.gc.ca1 (20%)
  • heise.de1 (20%)
  • roundcube.net1 (20%)
  • security-hub.ncsc.admin.ch1 (20%)