Hackers Actively Exploit Critical Roundcube SQL Injection (CVE‑2026‑48842)
What Happened – A pre‑authenticated SQL injection flaw (CVE‑2026‑48842) in Roundcube’s virtuser_query plugin was patched in May 2026, but the Canadian Centre for Cyber Security now confirms it is being actively exploited. The vulnerability lets an unauthenticated attacker bypass login, run arbitrary SQL commands, and exfiltrate the webmail database.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of un‑patched open‑source components that defeat authentication – a scenario continuous control‑assurance programs are built to detect and remediate.
- Highlights the need for real‑time evidence that critical services are running approved, patched versions, supporting defensible audit trails.
- Aligns with Verisq’s Access Controls capability: continuous verification that authentication mechanisms remain intact across the stack.
Who Is Affected – Providers of hosted email services, cPanel hosting operators, SaaS platforms that embed Roundcube, and any organization that runs the default Roundcube installation (technology, cloud‑infrastructure, and managed‑service sectors).
Recommended Actions
- Verify your Roundcube version; upgrade immediately to 1.6.16 or 1.7.1.
- If upgrade is not possible, disable or remove the
virtuser_queryplugin to close the attack surface. - Integrate automated patch‑validation checks into your continuous monitoring pipeline and retain evidence of compliance for audit readiness.
Technical Notes – The flaw is a pre‑authentication SQL injection in the virtuser_query plugin, allowing arbitrary database command execution without user interaction. No specific data type is disclosed, but the Roundcube database stores email headers, addresses, and potentially message bodies. Source: BleepingComputer