Roundcube Webmail SQL Injection Flaw Exploited In Active Cyber Attacks

Published:

The Canadian Centre for Cyber Security has warned that a recently patched vulnerability affecting Roundcube Webmail is being actively exploited in the wild. The security issue, identified as CVE-2026-48842 with a CVSS severity score of 8.1, affects the virtuser_query plugin in certain Roundcube Webmail versions and could allow unauthenticated attackers to execute arbitrary SQL statements against the application database. The vulnerability highlights continued risks associated with internet exposed email platforms and reinforces the importance of applying security updates promptly to reduce exposure to known threats.

The flaw impacts Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. According to security researchers, the issue originates from a preg_replace() backslash escape bypass that enables attackers to inject SQL commands without requiring authentication. If successfully exploited, the vulnerability could provide unauthorized access to sensitive information stored within the Roundcube database environment, including email account credentials and stored messages. SentinelOne noted that unauthenticated attackers could use the vulnerability to interact with the database backend through the virtuser_query plugin, potentially exposing confidential email related information. Roundcube addressed the issue by releasing security updates in May 2026 through versions 1.6.16 and 1.7.1, which included fixes for the vulnerability.

In an advisory update shared this week, the Canadian Centre for Cyber Security stated that the vulnerability is currently being exploited based on open source reporting. However, additional technical details about the observed exploitation activity have not been publicly disclosed. Data from the Shadowserver Foundation indicates that more than 523,000 Roundcube instances are exposed to the internet, with 10 hosts identified as vulnerable as of September 23, 2026. The scale of exposed systems demonstrates the importance of maintaining updated deployments, especially for applications that manage sensitive communications and authentication information. Organizations using affected Roundcube versions are advised to review their installations, apply available patches, and monitor systems for unusual activity associated with potential exploitation attempts.

Security vulnerabilities affecting Roundcube have previously attracted attention from threat actors due to the value of email communications and related account information. In July 2026, Proofpoint reported that a suspected China aligned threat group known as UNK_MassTraction was exploiting known Roundcube security weaknesses to deliver web shells or a post exploitation tool called VShell. Earlier in February 2026, two other vulnerabilities affecting the same product, CVE-2025-49113 and CVE-2025-68461, were added to the list of actively exploited vulnerabilities by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The repeated targeting of Roundcube demonstrates the need for organizations to maintain secure email infrastructure through timely patching, vulnerability monitoring, and broader security practices designed to reduce exposure from publicly known weaknesses.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img