Code Injection in Roundcube Webmail - CVE-2026-48844

 

Code Injection in Roundcube Webmail - CVE-2026-48844

Published: May 25, 2026 / Updated: September 25, 2026


Vulnerability identifier: #VU132219
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-48844
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject and execute arbitrary code.

The vulnerability exists due to code injection in the LDAP autovalues option when evaluating configured values. A remote user can supply crafted values in LDAP autovalues configuration to inject and execute arbitrary code.

Exploitation requires use of the LDAP autovalues option.


Affected software

Roundcube Webmail
Debian Linux
roundcube (Debian package)

How to mitigate CVE-2026-48844

Install security update from vendor's website.

Roundcube Webmail - addressed in versions 1.6.16, 1.7.1
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1

External References

Related Security Bulletins