Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild 2026-9-28 05:50:32 Author: securityaffairs.com(查看原文) 阅读量:15 收藏

Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild

Pierluigi Paganini September 28, 2026

Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise.

A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild. The Canadian Centre for Cyber Security added the warning to its advisory on September 21, citing open-source reporting and urging administrators to apply the available updates.

The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the virtuser_query plugin.

Roundcube released the fixes on May 24, 2026. The Canadian advisory now makes clear that patching wasn’t just about closing a theoretical bug. Someone is actually exploiting it in attacks in the wild.

“Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild.” reads the advisory published by The Canadian Centre for Cyber Security.

The bug is a pre-authentication SQL injection. An attacker doesn’t need a valid account or user interaction to reach the vulnerable code, which makes the exposure particularly uncomfortable for internet-facing webmail installations.

The problem is tied to how the virtuser_query plugin processes input. The plugin performs database lookups that map email addresses to mailbox usernames and uses PHP’s preg_replace() function with backslash escaping to try to prevent SQL injection.

Researchers found that this protection can be bypassed with specially crafted input containing backslash sequences. The escaping fails, allowing parts of the attacker’s input to reach the SQL query instead of being treated as harmless data.

That gives an unauthenticated attacker a direct path to the database behind Roundcube. Depending on the database permissions and configuration, successful exploitation could expose sensitive information stored there, including mailbox credentials and messages.

Researchers found that attackers can bypass this protection by sending specially crafted input containing backslash sequences. The escaping does not work as intended, allowing parts of the malicious input to reach the SQL query instead of being treated as harmless data.

This means an attacker does not need to authenticate to access the database behind Roundcube. Depending on the database configuration and permissions, successful exploitation could expose sensitive information, including mailbox credentials and stored messages.

“Unauthenticated attackers can inject SQL into Roundcube’s database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages.” warns SentinelOne.

Roundcube is an email application, and its database can contain information that becomes extremely useful once an attacker gets access to it. The timing is also worth noting. Roundcube fixed the problem in May, but the exploitation warning arrived in September. That’s enough time for organizations that didn’t apply the update to remain exposed while the vulnerability moved from a patched issue to an active attack target.

Threat actors have targeted multiple Roundcube flaws in attacks in the past. In July, Proofpoint reported activity by a suspected China-nexus actor tracked as UNK_MassTraction, which exploited known Roundcube vulnerabilities to deploy web shells or VShell, a post-exploitation tool.

The product had already appeared in CISA’s Known Exploited Vulnerabilities catalog earlier this year. In February, CISA listed CVE-2025-49113 and CVE-2025-68461 as actively exploited Roundcube vulnerabilities.

So CVE-2026-48842 isn’t an isolated case. Roundcube has repeatedly appeared in attacks where a public-facing mail interface provides an initial point of access.

For defenders, the first step is to check which Roundcube versions are running. Versions older than 1.6.16 or 1.7.1 should be considered vulnerable. Administrators should also check whether the virtuser_query plugin is enabled.

Installing the available patch is the main fix. If the plugin is not needed, disabling it can also reduce the risk. However, this should not replace updating Roundcube.

There is another issue to consider. If attackers exploited the vulnerability before the patch was installed, updating the software will not show whether the system was already compromised.

Organizations with exposed Roundcube servers should therefore review application logs for signs of exploitation. Requests containing unusual backslashes, quotes or SQL commands may be worth investigating. However, there are currently no confirmed indicators that can reliably identify exploitation.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CVE-2026-48842)




文章来源: https://securityaffairs.com/199882/security/roundcube-sql-injection-cve-2026-48842-is-now-being-exploited-in-the-wild.html
如有侵权请联系:admin#unsafe.sh