• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

CVE-2026-48842: Unauthenticated SQL Injection Flaw in Roundcube Webmail Now Targeted

Blog

Overview of CVE-2026-48842, the unauthenticated SQL injection flaw in Roundcube Webmail, shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-48842
CVSS 8.1 · High EPSS 0.8% (54th)

CVE-2026-48842 (CVSS 8.1, EPSS ≥ 54th pctl), published in May 2026, is an unauthenticated SQL injection flaw in Roundcube Webmail. Vulnerable instances warrant prompt attention due to the elevated risk signals. The flaw affects Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

Coalition has reported exploitation attempts against its honeypot, and on September 21st, the Canadian Centre for Cyber Security issued an update warning of the exploited status. However, CVE-2026-48842 has not been added to CISA’s Known Exploited Vulnerabilities (KEV) list.

Roundcube Webmail has a long record of in-the-wild exploitation, particularly in espionage-motivated attacks. CISA’s KEV catalog contains 11 Roundcube vulnerabilities. Previous attack campaigns have exploited SQL injection, Cross-Site Scripting (XSS) and other types of defects in Roundcube to steal credentials and sensitive email content, and establish persistent access to the victim’s servers.

CVE-2026-48842: unauthenticated SQL injection flaw in Roundcube Webmail

Start Your Free Trial

After CVE-2026-48842 was released in May 2026, Greenbone’s OPENVAS ENTERPRISE FEED added package detection across multiple Linux distributions [1][2][3][4][5][6][7], as well as remote banner detection for CVE-2026-48842 in Windows [8] and Linux [9] instances of Roundcube Webmail. The ENTERPRISE FEED includes regular detection for vulnerabilities affecting Roundcube Webmail, including more recent critical-severity flaws. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

Risk Assessment of CVE-2026-48842 in Roundcube Webmail

CVSS 8.1 · HighEPSS 0.8% (54th)Actively exploited

Roundcube is a PHP-based web application and server that connects to separate IMAP and SMTP mail services. The multilingual user interface is used to access and manage email messages, while the server contains sensitive credentials to an organization’s email system. CVE-2026-48842 is a network-reachable vulnerability, and no credentials or privileges are required for exploitation.

CVE-2026-48842 also warrants prompt attention due to additional elevated risk signals. Coalition has reported exploitation attempts against its honeypot. However, the flaw has not been added to CISA’s Known Exploited Vulnerabilities (KEV) list. Roundcube also has a long record of in-the-wild exploitation, particularly for cyber espionage. Recent Roundcube exploitation campaigns have targeted Ukrainian government organizations [1][2], government and military entities across Eastern Europe, including Albania, Greece, Moldova, and Türkiye [3], European government entities and think tanks [4], and physics and engineering departments at U.S. and Canadian universities [5].

A Technical Assessment of CVE-2026-48842 in Roundcube Webmail

From a technical standpoint, CVE-2026-48842 (CVSS 8.1, EPSS ≥ 54th pctl) is an unauthenticated SQL injection flaw [CWE-89] in the virtuser_query plugin. The root cause is a bypass of backslash character escaping when user-supplied input is processed by the preg_replace() function. Analyzing the fixed GitHub commits [1][2] reveals that the vulnerability is not a general failure to SQL-escape input fields. After sanitizing user-supplied credentials via $dbh->escape(), inputs were subsequently passed to PHP’s preg_replace() function.

$dbh->escape() inserted backslashes to protect SQL metacharacters. However, backslashes have a different contextual impact in the subsequent preg_replace() function, allowing an attacker to bypass the applied SQL statement protections. The fixed code now performs a literal placeholder substitution via the PHP str_replace() function.

Affected Versions and Mitigation

CVE-2026-48842 affects Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1. Although the vendor has released security updates for the affected release lines [1][2], users should review recent vulnerability scans of their Roundcube Webmail infrastructure since new critical and high-severity CVEs, such as CVE-2026-75003, have emerged since the patches for CVE-2026-48842 were released. Due to the product’s history of exploitation in the wild, users should upgrade to the most recent fixed versions.

The most recent stable release trains for Roundcube Webmail are:

Release Train Current Release Release Date Support Status

1.7.x

1.7.4

2026-09-06

Current stable release train; fully maintained

1.6.x

1.6.19

2026-09-06

LTS / low-maintenance release train; security and critical fixes only

Summary

CVE-2026-48842 is a high-severity pre-authentication SQL injection in Roundcube Webmail’s virtuser_query plugin affecting 1.6.x before 1.6.16 and 1.7.x before 1.7.1. Risk is elevated because active exploitation has been observed against honeypot instances and because of the product’s historical abuse in espionage-motivated attacks.

Start Your Free Trial

After its release in May 2026, Greenbone’s OPENVAS ENTERPRISE FEED added package detection for CVE-2026-48842 across multiple Linux distributions [1][2][3][4][5][6][7], as well as remote banner detection for CVE-2026-48842 in Windows [8] and Linux [9] instances of Roundcube Webmail. The ENTERPRISE FEED includes regular detection for vulnerabilities affecting Roundcube Webmail, including more recent critical-severity flaws. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

 

Contact Test Now Buy Here Back to Overview
Joseph Lee
Joseph Lee

Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.

He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.

Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.

LinkedIn

24. September 2026/by Joseph Lee
Share this entry
  • Share on LinkedIn
  • Share by Mail
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-09-24 14:08:442026-09-24 14:08:44CVE-2026-48842: Unauthenticated SQL Injection Flaw in Roundcube Webmail Now Targeted

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Link to: Patch Now! Heightened Risk Across Cisco Products in September 2026 Link to: Patch Now! Heightened Risk Across Cisco Products in September 2026 Patch Now! Heightened Risk Across Cisco Products in September 2026
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn