Vulnerability threat dossier

CVE-2026-48842

RoundcubeWebmail

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

VTP deterministic threat24.7of 100 · CVSS excluded

VTP analyst assessment

Roundcube pre-authentication SQL injection is reportedly under active exploitation

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence78%
Public exploitation · VTP factREPORTED

Assessment

CVE-2026-48842 is a pre-authentication SQL injection in Roundcube Webmail's virtuser_query plugin. SecurityWeek and The Hacker News report active exploitation. The flaw affects Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1. Attackers can reach the affected plugin without credentials, making exposed webmail services the priority.

Why it matters

  • SQL injection can expose, alter, or disrupt data handled by the affected webmail service.
  • The reported activity increases the need to remediate affected reachable instances promptly.

Evidence

4 record references and 3 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The active-exploitation reports are press reporting with unknown source independence.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use affected Roundcube versions, upgrade to 1.6.16 or 1.7.1 as applicable.

AI baseline history (4)
  1. BASELINE ASSESSED
    Roundcube pre-authentication SQL injection is reportedly under active exploitationgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Roundcube pre-authentication SQL injection under active-exploitation reportinggpt-5.6-terra · low
  3. BASELINE ASSESSED
    Reported exploitation of pre-authentication Roundcube SQL injectiongpt-5.6-terra · low
  4. BASELINE ASSESSED
    Roundcube virtuser_query pre-authentication SQL injectiongpt-5.6-terra · low
Technical severityHIGHCVSS 8.1 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0158th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.01; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

CERT ADVISORYNew CERT advisory
03

Claim provenance

Evidence and source independence

4publications detected
4underlying evidence chains

1 primary sources · 0 dependent secondary reports · 3 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:def0c2b3ed6c780876025f57fd119111704156f64582220f9fd15e2928673a83ACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:07493c6375dd3d347eb3aa07283b00eb4b36eb48306b9dd7adeb03938c675fb8ACTIVE
Evidence
04

Event history

Threat timeline

  1. 06:5725 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 13:2724 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  3. 00:0026 May
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-48842.

05

Original publications

Source record

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash

CVE-2025-49113CVE-2025-68461CVE-2026-48842
Separate evidence group
Original

Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .

CVE-2024-37383CVE-2025-49113CVE-2025-68461CVE-2026-48842
Separate evidence group
Original

Hackers now exploit critical Roundcube flaw in code injection attacks

A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]

CVE-2020-12641CVE-2020-35730CVE-2021-44026CVE-2023-5631CVE-2025-49113CVE-2025-68461CVE-2026-48842
Separate evidence group
Original

Multiples vulnérabilités dans Roundcube (26 mai 2026)

De multiples vulnérabilités ont été découvertes dans Roundcube. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

CVE-2026-48842
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score24.7vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.18 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency10 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-89
CPE records
0
Deterministic history records
8
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.