Technology

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Hacker News September 25, 2026 3 views
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Advertisement

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.

The flaw, identified as CVE-2026-48842 and rated 8.1 on the CVSS scale, is a pre‑authentication SQL injection that affects the virtuser_query plugin in Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue arises from a backslash in a preg_replace() call that allows attackers to inject malicious SQL code before a user logs in.

According to the Canadian Centre for Cyber Security, the vulnerability is already being exploited by threat actors in the wild, despite the fact that the vendor has released a patch to address the issue.

Users of affected Roundcube installations are urged to apply the latest security update immediately to prevent potential data breaches or unauthorized database access.

Roundcube is a widely used open‑source webmail client that powers many small and medium‑sized organisations, making timely updates critical to maintaining secure email services.

<small>Source: The Hacker News — read the original story there.</small>

How did this make you feel?

Never miss a story

Get the best of SpeakOX in your inbox. No spam, unsubscribe anytime.

Advertisement

Category
Technology

Advertisement