Roundcube Pre-Auth SQL Injection Vulnerability CVE-2026-48842 Actively Exploited in the Wild
A pre-authentication SQL injection vulnerability (CVE-2026-48842) in Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1 is actively exploited in the wild, allowing unauthenticated attackers to inject SQL and access sensitive email data. The Canadian Centre for Cyber Security warns of this critical flaw, which was patched in May 2026 but remains a target for threat actors.
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
The issue stems from a preg_replace() backslash
*** END OF TRANSMISSION ***