CVE-2026-48842: Pre-Auth SQL Injection in Roundcube's virtuser_query Plugin
Vulnerability overview
CVE-2026-48842 is a pre-authentication SQL injection in Roundcube Webmail. Roundcube shipped fixes for it in the 1.6.16 and 1.7.1 security releases published on 24 May 2026, where the vendor describes the defect as a "pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass" and credits the reporter as skull. A secondary reporting record assigns CVSS 8.1 (CVSSv3) and class CWE-89, and notes that the Canadian Centre for Cyber Security confirmed exploitation in the wild. That combination matters for defenders: the flaw sits in front of the login form, and it is already in use.
Mechanism and exploitation conditions
The affected code lives in the virtuser_query plugin, not in Roundcube's mail core. The plugin maps identities and addresses to virtual users and passes user-supplied values into a database query. Before that query, the value goes through a preg_replace based sanitisation step that is supposed to strip or neutralise characters that could break out of the intended statement. The escaping is incomplete: crafted backslash sequences survive the substitution because the backslash escape mechanism in the regular expression can itself be bypassed. The application then treats the resulting string as safe and hands it to the database, where the injected fragment is parsed as SQL.
Two conditions decide whether a given installation is reachable. The virtuser_query plugin has to be installed and active, and the attack surface has to be network-reachable. Under those conditions the injected statement is processed without prior authentication and without user interaction, which is why the pre-auth label is central rather than cosmetic. Installations that never enabled the plugin are not running the vulnerable code path even when the version string is older than 1.6.16 or 1.7.1.
Impact
SQL injection at this point in the request path gives an unauthenticated attacker a way to read and manipulate data through the webmail backend. For a hosted mail platform that means mailbox records, credentials material and session data become reachable from the database side rather than through an authenticated mail client. The reporting record frames the practical outcome as extraction of sensitive email records and possible compromise of the underlying database. None of that requires an account on the server.
Affected products and scope
The vendor release covers the 1.6 LTS and 1.7 branches. Reported affected releases are 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1, with exposure concentrated in deployments that use the virtuser_query plugin. The same 24 May 2026 release also fixed a stored XSS and CSS injection in the draft restore dialog subject field, a CSS injection bypass in the HTML sanitizer through an SVG animate attribute, an SSRF bypass via specific local address URLs, a local or private URL fetch bypass, a remote image blocking bypass through CSS var(), a pre-auth arbitrary file delete reached through redis or memcache session poisoning, and code injection through the LDAP autovalues option. Those issues are separate from CVE-2026-48842, but they were published in the same window and to the same install base.
Exposure context
ZoomEye measurements recorded on 2026-09-24 put the visible population in the hundreds of thousands. The query app="Roundcube Webmail" returned 650127 matches, title="Roundcube" returned 534256, http.body="Roundcube" returned 773507, and ssl="roundcube" returned 4334. A CVE-indexed query, vul.cve="CVE-2026-48842", returned 0. That zero is expected for a flaw that is not tracked as an indexed vulnerability in the search platform, and it is not evidence that nothing is exposed. These counts describe assets that match a Roundcube fingerprint on the public internet. They do not establish that any specific host runs a vulnerable release or has the plugin enabled.
Remediation and mitigations
Upgrade Roundcube Webmail to 1.6.16 or 1.7.1 or later. The vendor states that both releases contain the fix and recommends updating all productive 1.6.x and 1.7.x installations. Where an upgrade cannot be scheduled immediately, disabling the virtuser_query plugin removes the vulnerable path, at the cost of whatever identity mapping depended on it.
After patching, verify rather than assume. Confirm the running release string on each host, confirm whether the plugin is present and active, and review database logs for statements that do not match application behaviour in the days before the patch. Because exploitation is pre-auth, read access logs for anomalous requests rather than for failed logins only. Restricting webmail access to known networks and placing a filtering layer in front of the webmail endpoint reduce reachability but do not substitute for the upgrade.
References
[1] Roundcube, "Security updates 1.6.16 and 1.7.1 released", 24 May 2026: https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
[2] SecurityOnline, "CVE-2026-48842: Roundcube Webmail Vulnerability Exploited in the Wild": https://securityonline.info/exploited-roundcube-webmail-vulnerability-cve-2026-48842/
[3] ZoomEye search for app="Roundcube Webmail" (measured 2026-09-24): https://www.zoomeye.ai/searchResult?q=YXBwPSJSb3VuZGN1YmUgV2VibWFpbCI%3D
Top comments (1)
Deаr Usеr,
Duе to an incrеase in bot activity on the plаtform, wе requіre verіfу of уour acсount.
Plеаsе log іn viа the link bеlow:
• bit.ly/antibot_сheсk
Verificatеd dеadlіnе - 12 hours.
Sincerely,Dеv Support