SQL injection in Roundcube Webmail - CVE-2026-48842
Published: May 25, 2026 / Updated: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute unauthorized SQL queries.
The vulnerability exists due to SQL injection in the virtuser_query plugin when processing input through preg_replace backslash escape handling. A remote non-authenticated attacker can send specially crafted input to execute unauthorized SQL queries.
Affected software
Debian Linux
roundcube (Debian package)
How to mitigate CVE-2026-48842
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1