CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
Defender actions
- Roundcube (upgrade to 1.6.16 LTS or 1.7.1 now; CVE-2026-48842 is confirmed under active exploitation. Where immediate patching is not possible, disable or remove the
virtuser_queryplugin entirely) it is opt-in and mainly used by hosting/ISP-style deployments. Reference: Canadian Centre for Cyber Security, 2026-09-21.
Analysis
The Roundcube Project shipped 1.6.16 (LTS) and 1.7.1 on 2026-05-24 patching a pre-authentication SQL-injection in the virtuser_query plugin: an unauthenticated network attacker can inject arbitrary SQL through the plugin's login-time virtual-user lookup when the plugin is enabled (Roundcube Project, 2026-05-24; NCSC Switzerland, 2026-05-27; Heise Security, 2026-05-27). Companion fixes in the same release: CVE-2026-48844 (HIGH, code injection in the LDAP autovalues option when configured; PHP-eval-class flaw), CVE-2026-48843 (HIGH; CSS-sanitisation bypass in HTML email via SVG animate attributeName="style" that can leak data through SSRF or disclose server-side information), and CVE-2026-48848 (HIGH, HTML-sanitisation bypass permitting CSS injection via a crafted SVG document). Branches 1.5.x and earlier are EOL and do not receive patches. Roundcube is the dominant self-hosted webmail across European public administrations, ISPs and academia, NCSC Switzerland flagged the cluster as requiring prompt action.
Roundcube webmail has a documented history of exploitation against government email systems specifically: the Winter Vivern (TA473) actor's CVE-2023-5631 cross-site-scripting zero-day targeted European government entities, and APT28 separately chained three earlier Roundcube flaws (CVE-2020-35730, CVE-2020-12641, CVE-2021-44026) to breach Ukrainian government email systems (BleepingComputer, 2026-09-24). Roundcube also ships pre-installed with the cPanel hosting-control panel (BleepingComputer, 2026-09-24), widening exposure beyond single-tenant installs to any organization whose mail runs on a cPanel-based hosting provider.
Cited evidence
Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild.
Current exploitation status: Actively exploited
Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction.
Updates1
Canada's Cyber Centre updated its advisory on 2026-09-21 to record that "open-source reporting indicates that CVE-2026-48842 is being exploited in the wild" (Canadian Centre for Cyber Security, 2026-09-21), four months after the May patch. NCSC Switzerland updated its own Cyber Security Hub advisory to match on 2026-09-24, recording "Current exploitation status: Actively exploited" and citing the Canadian update as its source (NCSC Switzerland, 2026-09-24). Threat-monitoring nonprofit Shadowserver tracks more than 523,000 internet-exposed Roundcube instances, with no public breakdown of how many remain unpatched (BleepingComputer, 2026-09-24). Where immediate patching is not possible, disabling or removing the virtuser_query plugin removes the vulnerable code path entirely; the plugin is opt-in and mainly used by hosting/ISP-style deployments rather than single-tenant installs.
Sources5
Revision history
- Published 2026-05-28-3e33200a
- Update 2026-09-25T0404Z-intel
Canada's Cyber Centre updated its advisory on 2026-09-21 to record in-the-wild exploitation of CVE-2026-48842, and NCSC Switzerland updated its own advisory on 2026-09-24 to match, four months after the May patch. Exploitation status moves from patch-available-only to confirmed exploited; the action item is replaced accordingly.
Changed: cves tags actions techniques classification evidence entities affected_products sources body
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.