CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-05-28
HIGHCVE-2026-48842 +3exploitedupdatedNATOA2vulnerability

CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)

Defender actions

  • Roundcube (upgrade to 1.6.16 LTS or 1.7.1 now; CVE-2026-48842 is confirmed under active exploitation. Where immediate patching is not possible, disable or remove the virtuser_query plugin entirely) it is opt-in and mainly used by hosting/ISP-style deployments. Reference: Canadian Centre for Cyber Security, 2026-09-21.

Analysis

The Roundcube Project shipped 1.6.16 (LTS) and 1.7.1 on 2026-05-24 patching a pre-authentication SQL-injection in the virtuser_query plugin: an unauthenticated network attacker can inject arbitrary SQL through the plugin's login-time virtual-user lookup when the plugin is enabled (Roundcube Project, 2026-05-24; NCSC Switzerland, 2026-05-27; Heise Security, 2026-05-27). Companion fixes in the same release: CVE-2026-48844 (HIGH, code injection in the LDAP autovalues option when configured; PHP-eval-class flaw), CVE-2026-48843 (HIGH; CSS-sanitisation bypass in HTML email via SVG animate attributeName="style" that can leak data through SSRF or disclose server-side information), and CVE-2026-48848 (HIGH, HTML-sanitisation bypass permitting CSS injection via a crafted SVG document). Branches 1.5.x and earlier are EOL and do not receive patches. Roundcube is the dominant self-hosted webmail across European public administrations, ISPs and academia, NCSC Switzerland flagged the cluster as requiring prompt action.

Roundcube webmail has a documented history of exploitation against government email systems specifically: the Winter Vivern (TA473) actor's CVE-2023-5631 cross-site-scripting zero-day targeted European government entities, and APT28 separately chained three earlier Roundcube flaws (CVE-2020-35730, CVE-2020-12641, CVE-2021-44026) to breach Ukrainian government email systems (BleepingComputer, 2026-09-24). Roundcube also ships pre-installed with the cPanel hosting-control panel (BleepingComputer, 2026-09-24), widening exposure beyond single-tenant installs to any organization whose mail runs on a cPanel-based hosting provider.

Cited evidence

Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild.

Canadian Centre for Cyber Security 2026-09-21

Current exploitation status: Actively exploited

NCSC Switzerland post 12596

Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction.

BleepingComputer 2026-09-24

Updates1

Update

Canada's Cyber Centre updated its advisory on 2026-09-21 to record that "open-source reporting indicates that CVE-2026-48842 is being exploited in the wild" (Canadian Centre for Cyber Security, 2026-09-21), four months after the May patch. NCSC Switzerland updated its own Cyber Security Hub advisory to match on 2026-09-24, recording "Current exploitation status: Actively exploited" and citing the Canadian update as its source (NCSC Switzerland, 2026-09-24). Threat-monitoring nonprofit Shadowserver tracks more than 523,000 internet-exposed Roundcube instances, with no public breakdown of how many remain unpatched (BleepingComputer, 2026-09-24). Where immediate patching is not possible, disabling or removing the virtuser_query plugin removes the vulnerable code path entirely; the plugin is opt-in and mainly used by hosting/ISP-style deployments rather than single-tenant installs.

Sources5

Revision history

  1. Published 2026-05-28-3e33200a
  2. Update 2026-09-25T0404Z-intel

    Canada's Cyber Centre updated its advisory on 2026-09-21 to record in-the-wild exploitation of CVE-2026-48842, and NCSC Switzerland updated its own advisory on 2026-09-24 to match, four months after the May patch. Exploitation status moves from patch-available-only to confirmed exploited; the action item is replaced accordingly.

    Changed: cves tags actions techniques classification evidence entities affected_products sources body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.