CVE-2026-48842
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
- CVSS
- 8.1
- EPSS
- 0.009 (57.6th percentile)
- CISA KEV
- Not listed
- Exploitation
- none
- Public exploits
- None seen
- State
- PUBLISHED
Coverage

The Hacker News
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail…
SecurityWeek
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
What we observed
No signals recorded