Roundcube SQL injection flaw actively exploited in the wild
The Canadian Centre for Cyber Security warns that CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail, is being actively exploited by attackers.
The Canadian Centre for Cyber Security has issued a warning that a critical vulnerability in Roundcube Webmail is currently being exploited by threat actors. This security flaw, identified as CVE-2026-48842, allows unauthenticated attackers to execute arbitrary SQL commands against the application's database. Although patches were released in May 2026, active exploitation campaigns have been detected in the wild as of late September 2026.
What happened
The vulnerability exists within the virtuser_query plugin of Roundcube Webmail. It affects version 1.6.x prior to 1.6.16 and version 1.7.x prior to 1.7.1. The root cause is a bypass of backslash escaping in the preg_replace() function. This technical oversight enables attackers to inject malicious SQL statements without needing valid login credentials. Once exploited, the attacker can interact directly with the database backend.
According to SentinelOne, this access potentially exposes mail account credentials and stored messages. The Canadian Centre for Cyber Security confirmed the active exploitation status this week, citing open-source intelligence reports. While the specific tactics and targets of the current campaign remain undisclosed, the high CVSS score of 8.1 indicates a severe risk to confidentiality and integrity. Patches addressing this issue were made available by the Roundcube team in May 2026.
Data from the Shadowserver Foundation highlights the scale of potential exposure. There are more than 523,000 Roundcube instances currently exposed to the public internet. As of September 23, 2026, ten of these hosts were flagged as still running vulnerable versions. This suggests that while the majority of administrators may have updated, a small but significant number of servers remain open to attack.
Key details
- Vulnerability ID: CVE-2026-48842 with a CVSS score of 8.1.
- Affected Versions: Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
- Attack Vector: Pre-authentication SQL injection via the
virtuser_queryplugin. - Root Cause: A
preg_replace()backslash escape bypass allowing arbitrary SQL injection. - Patch Status: Fixed in versions 1.6.16 and 1.7.1, released in May 2026.
- Current Threat: Actively exploited in the wild as of September 2026.
Background
SQL injection is a common web security vulnerability where an attacker interferes with the queries an application makes to its database. In a pre-authentication scenario, the attacker does not need a username or password to trigger the exploit. This makes such flaws particularly dangerous for internet-facing services like webmail, which are designed to be accessible from anywhere. The virtuser_query plugin is used to map virtual users to system users, often involving database lookups. If input sanitization fails, as it did here with the backslash escape bypass, the database executes attacker-controlled commands.
Roundcube has been a frequent target for advanced persistent threats due to the sensitive nature of email data. In July 2026, Proofpoint identified a suspected China-aligned adversary, tracked as UNK_MassTraction, exploiting older Roundcube flaws to deploy web shells and a tool called VShell. Earlier in February 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two other Roundcube vulnerabilities to its list of known exploited vulnerabilities. This pattern indicates that threat actors continuously monitor and weaponize flaws in popular self-hosted email solutions.
Why it matters
For teams running their own infrastructure, email servers are often considered critical internal tools that may receive less immediate scrutiny than customer-facing web applications. However, because they handle sensitive communications and credentials, they are high-value targets. An successful exploitation of CVE-2026-48842 could lead to a complete compromise of user emails and authentication tokens. This data can be used for further lateral movement within a network or for corporate espionage.
The fact that exploitation is active means that automated scanners are likely probing for unpatched instances right now. With over half a million instances exposed to the internet, the attack surface is vast. Even if only a small fraction are unpatched, the ease of exploitation means that any remaining vulnerable server is at imminent risk. Administrators cannot rely on obscurity; the vulnerability is well-known and the exploit method is straightforward for those with access to the patch details.
What you can do
- Verify your version: Check your Roundcube installation immediately to determine if you are running a version prior to 1.6.16 or 1.7.1.
- Apply patches: If you are on an affected version, upgrade to the latest stable release provided by Roundcube.
- Disable the plugin: If upgrading is not immediately possible, consider disabling the
virtuser_queryplugin if it is not essential for your user management workflow. - Audit logs: Review web server and database logs for unusual query patterns or failed login attempts that might indicate exploitation attempts.
- Restrict access: Use firewalls or reverse proxies to limit access to the webmail interface to trusted IP ranges if feasible.
- Monitor exposure: Use external scanning tools to verify if your Roundcube instance is visible to the public internet and ensure it is not flagged as vulnerable.
"Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne said.



