Skip to content
THREATWIRE

CVE

HighPoC Available

CVE-2026-48842

Roundcube virtuser_query SQL injection

Roundcube 1.6 before 1.6.16 and 1.7 before 1.7.1 have a pre-authentication SQL injection in virtuser_query. NVD scores it 8.1. A public PoC repository exists. CISA has not listed it.

CVSS
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Class
SQLi
Status
PoC Available
KEV
Not in CISA KEV
0-day
No
Vendor
Roundcube
Products
Roundcube Webmail
Affected
1.6.x before 1.6.16 and 1.7.x before 1.7.1, when the virtuser_query plugin is in use.
Fixed
1.6.16 and 1.7.1, announced 24 May 2026.
Published
25 May 2026
Updated
5 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-48842 is a pre-authentication SQL injection in Roundcube Webmail’s virtuser_query plugin. NVD says 1.6.x before 1.6.16 and 1.7.x before 1.7.1 are affected, and describes a backslash-escaping bypass around preg_replace(). The CVSS 3.1 score is 8.1. Attack complexity is high. No privileges and no user interaction are required. Roundcube announced 1.6.16 and 1.7.1 on 24 May 2026.

A public repository, 4minx/CVE-2026-48842, was created on 27 September 2026. That is PoC Available. The fix shipped months earlier, so this is not a 0-day. CISA’s Known Exploited Vulnerabilities catalog does not list the CVE. September reporting says the Canadian Centre for Cyber Security warned of exploitation and cited open-source reporting. That warning is not a CISA listing and it is not a sentence in the May Roundcube release note, so this record stays at PoC Available. The request is not reprinted.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-48842