The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
The issue stems from a preg_replace() backslash escape bypass that allows attackers to inject arbitrary SQL statements without authentication.
“Unauthenticated attackers can inject SQL into Roundcube’s database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages,” SentinelOne said.
Patches for the vulnerability were released by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
In an update shared this week, the Cyber Centre said the security flaw is being actively exploited in the wild, citing open-source reporting. No additional details of the exploitation activity have been disclosed.


Leave a Reply