---
schema: 1
kind: vulnerability
title: CVE-2026-48842 — Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
headline: CVE-2026-48842 — Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
summary: "Roundcube Webmail 1.6.16 / 1.7.1 — pre-auth SQL injection in the virtuser_query plugin (CVE-2026-48842, CVSS 8.1) plus three further high-severity flaws. NCSC.ch published an advisory on 2026-05-27 flagging the cluster; Roundcube is the dominant self-hosted webmail across European public administrations and academic institutions (Roundcube Project, 2026-05-24; NCSC-CH, 2026-05-27; Heise, 2026-05-27). The companion bugs cover an LDAP autovalues code-injection (CVE-2026-48844), an SVG-based CSS-sanitisation bypass (CVE-2026-48848) and an SSRF / info-disclosure via crafted SVG animate (CVE-2026-48843)."
discovered_at: "2026-05-28T05:00:06Z"
updated_at: "2026-09-25T04:29:00Z"
event_date: 2026-05-27
run_id: 2026-05-28-3e33200a
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - sqli
  - info-disclosure
  - patch-available
  - actively-exploited
regions:
  - europe
  - global
sectors:
  - public-sector
  - education
  - telco
entities: ["product:roundcube-webmail"]
techniques: [T1190]
affected_products: ["Roundcube Webmail"]
cves:
  - id: CVE-2026-48842
    cvss: "8.1"
    epss: null
    type: sqli
    vector: user-interaction
    auth: pre-auth
    status:
      - patch-available
      - exploited
  - id: CVE-2026-48843
    cvss: n/a
    epss: null
    type: sqli
    vector: user-interaction
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-48844
    cvss: n/a
    epss: null
    type: sqli
    vector: user-interaction
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-48848
    cvss: n/a
    epss: null
    type: sqli
    vector: user-interaction
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1"
    publisher: Roundcube Project
    role: primary
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12596"
    publisher: NCSC Switzerland post 12596
    role: corroborating
  - url: "https://www.heise.de/news/Roundcube-Webmail-Instanzen-mit-Schadcode-attackierbar-11307545.html"
    publisher: Heise Security
    role: corroborating
  - url: "https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503"
    publisher: "Canadian Centre for Cyber Security"
    date: "2026-09-21"
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/"
    publisher: "BleepingComputer"
    date: "2026-09-24"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild."
    publisher: "Canadian Centre for Cyber Security"
    source_url: "https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503"
  - quote: "Current exploitation status: Actively exploited"
    publisher: "NCSC Switzerland post 12596"
    source_url: "https://security-hub.ncsc.admin.ch/#/posts/12596"
  - quote: "Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction."
    publisher: "BleepingComputer"
    source_url: "https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/"
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "**Roundcube — upgrade to 1.6.16 LTS or 1.7.1 now; CVE-2026-48842 is confirmed under active exploitation.** Where immediate patching is not possible, disable or remove the `virtuser_query` plugin entirely — it is opt-in and mainly used by hosting/ISP-style deployments. Reference: [Canadian Centre for Cyber Security, 2026-09-21](https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503)."
updates:
  - at: "2026-09-25T04:29:00Z"
    run_id: 2026-09-25T0404Z-intel
    type: update
    summary: >
      Canada's Cyber Centre updated its advisory on 2026-09-21 to record in-the-wild exploitation of
      CVE-2026-48842, and NCSC Switzerland updated its own advisory on 2026-09-24 to match, four months
      after the May patch. Exploitation status moves from patch-available-only to confirmed exploited;
      the action item is replaced accordingly.
    fields: [cves, tags, actions, techniques, classification, evidence, entities, affected_products, sources, body]
migrated_from: briefs/2026-05-28.md
---

The Roundcube Project shipped 1.6.16 (LTS) and 1.7.1 on 2026-05-24 patching a pre-authentication SQL-injection in the `virtuser_query` plugin: an unauthenticated network attacker can inject arbitrary SQL through the plugin's login-time virtual-user lookup when the plugin is enabled ([Roundcube Project, 2026-05-24](https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1); [NCSC Switzerland, 2026-05-27](https://security-hub.ncsc.admin.ch/#/posts/12596); [Heise Security, 2026-05-27](https://www.heise.de/news/Roundcube-Webmail-Instanzen-mit-Schadcode-attackierbar-11307545.html)). Companion fixes in the same release: CVE-2026-48844 (HIGH — code injection in the LDAP `autovalues` option when configured; PHP-eval-class flaw), CVE-2026-48843 (HIGH — CSS-sanitisation bypass in HTML email via SVG `animate attributeName="style"` that can leak data through SSRF or disclose server-side information), and CVE-2026-48848 (HIGH — HTML-sanitisation bypass permitting CSS injection via a crafted SVG document). Branches 1.5.x and earlier are EOL and do not receive patches. Roundcube is the dominant self-hosted webmail across European public administrations, ISPs and academia — NCSC Switzerland flagged the cluster as requiring prompt action.

Roundcube webmail has a documented history of exploitation against government email systems specifically: the Winter Vivern (TA473) actor's CVE-2023-5631 cross-site-scripting zero-day targeted European government entities, and APT28 separately chained three earlier Roundcube flaws (CVE-2020-35730, CVE-2020-12641, CVE-2021-44026) to breach Ukrainian government email systems ([BleepingComputer, 2026-09-24](https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/)). Roundcube also ships pre-installed with the cPanel hosting-control panel ([BleepingComputer, 2026-09-24](https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/)), widening exposure beyond single-tenant installs to any organization whose mail runs on a cPanel-based hosting provider.

**Defender takeaway:** since the vulnerable path is pre-authentication, hunt web-access and authentication logs for the Roundcube login endpoint for anomalous or successful authentications with no matching credential-verification event, and for malformed or escaped characters in fields that feed the `virtuser_query` lookup; correlate against database-query logs for the Roundcube service account issuing queries structurally inconsistent with the configured template. **Triage:** a legitimate authentication traces to a real, logged credential check; an authentication event on this path with no matching verification, or a query the configured template would never generate, is the signal.

## Update — 2026-09-25T04:29:00Z

Canada's Cyber Centre updated its advisory on 2026-09-21 to record that "open-source reporting indicates that CVE-2026-48842 is being exploited in the wild" ([Canadian Centre for Cyber Security, 2026-09-21](https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503)), four months after the May patch. NCSC Switzerland updated its own Cyber Security Hub advisory to match on 2026-09-24, recording "Current exploitation status: Actively exploited" and citing the Canadian update as its source ([NCSC Switzerland, 2026-09-24](https://security-hub.ncsc.admin.ch/#/posts/12596)). Threat-monitoring nonprofit Shadowserver tracks more than 523,000 internet-exposed Roundcube instances, with no public breakdown of how many remain unpatched ([BleepingComputer, 2026-09-24](https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/)). Where immediate patching is not possible, disabling or removing the `virtuser_query` plugin removes the vulnerable code path entirely — the plugin is opt-in and mainly used by hosting/ISP-style deployments rather than single-tenant installs.
