CVE-2026-48842
Roundcube virtuser_query SQL injection
Roundcube 1.6 before 1.6.16 and 1.7 before 1.7.1 have a pre-authentication SQL injection in virtuser_query. NVD scores it 8.1. A public PoC repository exists. CISA has not listed it.
- CVSS
- 8.1
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Class
- SQLi
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Roundcube
- Products
- Roundcube Webmail
- Affected
- 1.6.x before 1.6.16 and 1.7.x before 1.7.1, when the virtuser_query plugin is in use.
- Fixed
- 1.6.16 and 1.7.1, announced 24 May 2026.
- CWE
- CWE-89
- Published
- 25 May 2026
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-48842 is a pre-authentication SQL injection in Roundcube Webmail’s virtuser_query plugin. NVD says 1.6.x before 1.6.16 and 1.7.x before 1.7.1 are affected, and describes a backslash-escaping bypass around preg_replace(). The CVSS 3.1 score is 8.1. Attack complexity is high. No privileges and no user interaction are required. Roundcube announced 1.6.16 and 1.7.1 on 24 May 2026.
A public repository, 4minx/CVE-2026-48842, was created on 27 September 2026. That is PoC Available. The fix shipped months earlier, so this is not a 0-day. CISA’s Known Exploited Vulnerabilities catalog does not list the CVE. September reporting says the Canadian Centre for Cyber Security warned of exploitation and cited open-source reporting. That warning is not a CISA listing and it is not a sentence in the May Roundcube release note, so this record stays at PoC Available. The request is not reprinted.