AI Weekly Malaysia

Back to items Summaries

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

ID
28486
Status
summarized
Published
25 Sep 2026, 6:14 PM
Fetched
25 Sep 2026, 6:46 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.0
Created
25 Sep 2026, 6:47 PM
Tags
Audience
developers

What happened

The Canadian Centre for Cyber Security says CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail's virtuser_query plugin (CVSS 8.1), is being actively exploited in the wild. It affects 1.6.x before 1.6.16 and 1.7.x before 1.7.1, caused by a preg_replace() backslash escape bypass that lets unauthenticated attackers inject SQL and potentially expose mail credentials and stored messages. Roundcube shipped fixes back in May 2026 (1.6.16 and 1.7.1); Shadowserver counted over 523,000 internet-exposed Roundcube instances but only 10 flagged as vulnerable hosts as of September 23, 2026.

Why it matters

If you or a client still runs a self-hosted webmail stack on Roundcube 1.6.x or 1.7.x, the concrete decision is: confirm you are on 1.6.16 or 1.7.1 and not just on a patched-but-older branch, because the patch is four months old and exploitation is now confirmed rather than theoretical. If your organisation does not run Roundcube, this changes nothing for you this week — the exploitation details were not disclosed, and the Shadowserver figure of 10 vulnerable hosts out of 523,000 exposed instances suggests most deployments are already patched.

Discussion angle

The measurement gap is the interesting part: 523,000 exposed instances versus only 10 flagged vulnerable on Sept 23, yet the advisory says active exploitation. How much should you trust 'vulnerable host' counts when deciding how fast to patch a mail server — and who on your team actually owns patch duty for infrastructure nobody's product roadmap mentions?

Top