The Roundcube SQL injection is not in the CISA catalog
CVE-2026-48842 is a pre-authentication SQL injection in Roundcube virtuser_query, fixed in May 2026. A public PoC exists. CISA has not listed it, so ThreatWire does not mark Active Exploitation.
Published 5 Oct 2026
What happened
Roundcube published security updates 1.6.16 and 1.7.1 on 24 May 2026. NVD recorded CVE-2026-48842 the next day. It is a pre-authentication SQL injection in the virtuser_query plugin. The weakness is CWE-89. The CVSS 3.1 score is 8.1, with high attack complexity and no required privileges or user interaction. NVD describes the bug as a backslash-escaping bypass around preg_replace().
Who is affected
The ranges are 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The plugin name in the advisory is virtuser_query. An instance that does not use that plugin is outside the sentence NVD publishes. Versions already on 1.6.16, 1.7.1, or later are outside the range.
What is confirmed
The vendor fix dates and version numbers are the May release note and the NVD entry. A public repository, 4minx/CVE-2026-48842, was created on 27 September 2026 and describes itself as a proof of concept. That is enough for PoC Available. The repository is months after the fix, so this is not a 0-day.
What is not confirmed
Posts in September call the bug exploited in the wild. The Hacker News report says the Canadian Centre for Cyber Security warned of exploitation and cited open-source reporting. That is a real report. It is not an entry in CISA’s Known Exploited Vulnerabilities catalog. The catalog was checked for this CVE and it is absent. The May Roundcube announcement is the vendor fix note. It is not a vendor statement that attacks are underway. ThreatWire therefore does not use Active Exploitation. The status stays PoC Available.
What to do
Install Roundcube 1.6.16 or 1.7.1, or a later release on those lines. Instances that do not need virtuser_query should not be left on a vulnerable build while the question of exploitation is argued. The request used by the public repository is not reprinted here.
Sources: the Roundcube news post of 24 May 2026, NVD, the CISA KEV catalog check, The Hacker News report of 25 September 2026, and the public repository linked from the record.