Code Injection in Roundcube Webmail - CVE-2026-48844
Published: May 25, 2026 / Updated: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to inject and execute arbitrary code.
The vulnerability exists due to code injection in the LDAP autovalues option when evaluating configured values. A remote user can supply crafted values in LDAP autovalues configuration to inject and execute arbitrary code.
Exploitation requires use of the LDAP autovalues option.
Affected software
Debian Linux
roundcube (Debian package)
How to mitigate CVE-2026-48844
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1