Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
- ID
- 28486
- Status
- summarized
- Published
- 25 Sep 2026, 6:14 PM
- Fetched
- 25 Sep 2026, 6:46 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.0
- Created
- 25 Sep 2026, 6:47 PM
- Tags
- Audience
- developers
What happened
The Canadian Centre for Cyber Security says CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail's virtuser_query plugin (CVSS 8.1), is being actively exploited in the wild. It affects 1.6.x before 1.6.16 and 1.7.x before 1.7.1, caused by a preg_replace() backslash escape bypass that lets unauthenticated attackers inject SQL and potentially expose mail credentials and stored messages. Roundcube shipped fixes back in May 2026 (1.6.16 and 1.7.1); Shadowserver counted over 523,000 internet-exposed Roundcube instances but only 10 flagged as vulnerable hosts as of September 23, 2026.
Why it matters
If you or a client still runs a self-hosted webmail stack on Roundcube 1.6.x or 1.7.x, the concrete decision is: confirm you are on 1.6.16 or 1.7.1 and not just on a patched-but-older branch, because the patch is four months old and exploitation is now confirmed rather than theoretical. If your organisation does not run Roundcube, this changes nothing for you this week — the exploitation details were not disclosed, and the Shadowserver figure of 10 vulnerable hosts out of 523,000 exposed instances suggests most deployments are already patched.
Discussion angle
The measurement gap is the interesting part: 523,000 exposed instances versus only 10 flagged vulnerable on Sept 23, yet the advisory says active exploitation. How much should you trust 'vulnerable host' counts when deciding how fast to patch a mail server — and who on your team actually owns patch duty for infrastructure nobody's product roadmap mentions?