Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 25, 2026 · 7 min read

Roundcube SQL Injection CVE-2026-48842 Now Exploited

Roundcube fixed an unauthenticated SQL injection in its virtuser_query plugin on May 24, 2026. On September 21, the Canadian Centre for Cyber Security updated its advisory to say the flaw is being exploited in the wild.

Four months is a long time to leave a webmail login form open to SQL injection. That is roughly the gap between Roundcube shipping a fix for CVE-2026-48842 and Canada's national cyber agency warning that attackers are now using it. On Monday, September 21, the Cyber Centre added one line to advisory AV26-503: "Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild."

The bug sits in a plugin most Roundcube servers never load. For the ones that do, it hands an unauthenticated stranger a query prompt against the database behind the webmail.

Key Takeaways

  • CVE-2026-48842 is an unauthenticated SQL injection in Roundcube's bundled virtuser_query plugin, fixed in Roundcube 1.6.16 and 1.7.1 on May 24, 2026.
  • The Canadian Centre for Cyber Security updated advisory AV26-503 on September 21, 2026 to say the flaw is being exploited in the wild, 120 days after the patch.
  • Roundcube ships virtuser_query switched off, so only servers where an administrator added it to the plugin list and configured its SQL queries are exposed.
  • CISA's Known Exploited Vulnerabilities catalog already lists 11 Roundcube flaws, but CVE-2026-48842 was not among them as of the September 24, 2026 catalog release.
  • Patching to 1.6.16 or 1.7.1 closes this bug, yet the current releases, 1.6.19 and 1.7.4, carry 29 further security fixes shipped since May.
A server rack in a dim university data centre with a system administrator's open laptop beside it, the screen showing a blank webmail login form

What Is CVE-2026-48842?

CVE-2026-48842 is a SQL injection in Roundcube Webmail's virtuser_query plugin that an attacker can trigger without logging in. The NVD record describes it as affecting "Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1," classifies it as CWE-89, and carries a MITRE score of 8.1 (High) with the vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.

The plugin maps login names to email addresses, identities and IMAP hosts by running SQL queries the administrator writes into the config, with %u or %m standing in for the username or email address typed at login. Before the fix, the plugin escaped that value and then spliced it into the query with PHP's preg_replace(). The catch is that preg_replace() gives backslashes in its replacement string a meaning of their own, so a crafted run of backslashes could undo the escaping and let a quote character through. Roundcube's release notes call it a "preg_replace backslash escape bypass" and credit a researcher named skull.

The fix commit is four one line changes: every preg_replace() becomes str_replace(), which treats the replacement as plain text. Two of the plugin's four lookups hang off Roundcube's authenticate hook, which fires when someone submits the login form. That is why no account is needed.

Is virtuser_query Enabled by Default?

No. The plugin ships inside every Roundcube download, but it stays inert until an administrator turns it on. Roundcube's defaults file sets $config['plugins'] = [];, and the sample config activates only archive and zipdownload. Even when listed, the plugin source registers no hooks unless $config['virtuser_query'] contains at least one query.

That changes how to read the headline number. Shadowserver tracks "over 523,000 Roundcube instances exposed on the Internet," according to BleepingComputer's report, which also notes there is no data on how many are honeypots or already patched. The vulnerable population is a subset of that subset: unpatched servers whose operators chose database driven user mapping. Nobody has published that figure.

The operators most likely to have chosen it run virtual mail hosting, where mailbox users live in SQL tables rather than system accounts. BleepingComputer points out that Roundcube comes preinstalled with cPanel. Neither the Cyber Centre nor Roundcube says whether cPanel or any other hosting panel enables virtuser_query, and we found no public statement either way.

The Exploitation Timeline

  • May 24, 2026: Roundcube publishes 1.6.16 and 1.7.1, fixing eight security issues including the virtuser_query injection.
  • May 25: MITRE publishes CVE-2026-48842, and the Cyber Centre issues the original AV26-503 advisory.
  • June 3: The flaw is posted to the oss-security mailing list with the CVE number attached, since Roundcube's own announcement listed none.
  • September 21: The Cyber Centre updates AV26-503 to report exploitation in the wild.
  • September 24: BleepingComputer reports the exploitation.

What the timeline lacks matters as much as what it holds. The Cyber Centre attributes its warning to "open-source reporting" without naming the source, an actor or a target. No indicators of compromise have been published, and we found no public proof of concept. As of September 24, CISA's own enrichment on the NVD record still marked exploitation as "none," so US federal agencies have no binding patch deadline yet.

How Do Admins Check, Patch, or Disable the Plugin?

Start by finding out whether the plugin is live, then upgrade past the minimum. The Roundcube GitHub releases page lists every build since May.

  • Check exposure. Search config/config.inc.php for virtuser_query. If it appears in $config['plugins'] and a $config['virtuser_query'] block defines queries, the server was exploitable until patched.
  • Check the version. Roundcube stores its version in the RCMAIL_VERSION constant in program/include/iniset.php. Anything on 1.6 below 1.6.16, or on 1.7 below 1.7.1, is affected.
  • Upgrade to current, not minimum. Roundcube has shipped three more security releases since May: 1.6.17 and 1.7.2 on July 5, 1.6.18 and 1.7.3 on August 9, and 1.6.19 and 1.7.4 on September 6. Together they fix 29 more issues, including a zero click stored XSS via TNEF MIME tag injection.
  • Disable if you cannot upgrade. Remove virtuser_query from $config['plugins']. That also switches off the lookups it performs, such as mapping a login address to an IMAP username, so test logins before rolling it out.
  • Hunt. With no published indicators, a reasonable starting point is web and database logs for login attempts carrying runs of backslashes in the username field, since the bypass depends on them. If $config['virtuser_query_dsn'] points to a separate mail user database, treat that database as in scope too, and rotate its credentials if anything looks wrong.

If Roundcube came bundled with a hosting control panel, check the version the panel actually deployed rather than the one on Roundcube's release page.

Why Does Roundcube Keep Getting Exploited?

Because it fronts the mailboxes of governments and institutions that state backed groups want to read. CISA's KEV catalog lists 11 Roundcube flaws, the oldest (CVE-2017-16651) added on November 3, 2021 and the newest two on February 20, 2026. BleepingComputer's count of 11 "since May 2022" slightly misdates the first entry.

The track record matters for journalists and NGO staff whose organizations host their own mail. BleepingComputer reports that Winter Vivern (TA473) used the XSS zero day CVE-2023-5631 against European government entities, and that APT28 used CVE-2020-35730, CVE-2020-12641 and CVE-2021-44026 to breach Ukrainian government email systems. One of those three, CVE-2021-44026, was also a Roundcube SQL injection. APT28 returned in 2026 with newer bugs, as covered in our report on Russia reading the email of Ukraine's anticorruption prosecutors.

CVE-2026-48842 differs from the February pair, CVE-2025-49113 and CVE-2025-68461, which we covered in our earlier Roundcube exploitation report. CVE-2025-49113 needed a logged in user and reached code execution. This one needs no login but only reaches the database, and only where a nondefault plugin is on.

What This Means for Your Inbox

If your university, employer or web host gives you mail through Roundcube, you cannot patch this yourself, and the data at risk is not only yours. Roundcube's database schema includes tables for users, sessions, contacts, collected addresses and sender identities. SQL access to that database exposes who you correspond with and how you sign your messages, which is the raw material for a convincing impersonation of you to your own contacts.

Roundcube's default branding is "Roundcube Webmail," so if that name appears on your webmail login screen, ask the administrator two questions: which version is running, and whether virtuser_query is enabled. Watch for replies from contacts to messages you never sent. Shared webmail concentrates risk the way the Jewelbug government webmail intrusion and the cPanel EmailTrack root flaw showed: one server, every mailbox on it.

For sources and reporters, the takeaway is simpler. A self hosted webmail server that trails the current Roundcube release by even one cycle deserves the same scrutiny as an unpatched phone.

Looking Ahead

Watch for two things. First, whether CISA adds CVE-2026-48842 to the KEV catalog, which would give US federal agencies a binding patch deadline. Second, whether the "open-source reporting" behind Canada's update surfaces with indicators defenders can match against their logs.

A word on labels, too. Some headlines describe this as a code injection attack. The CVE record classifies it as SQL injection. The code injection fix in the same May release was a separate bug in the LDAP autovalues option. Triage by CVE ID, not by headline.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.