Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Hackers Actively Exploit Critical Roundcube SQL Injection (CVE‑2026‑48842)

A pre‑authenticated SQL injection (CVE‑2026‑48842) in Roundcube’s virtuser_query plugin is being actively exploited, allowing attackers to bypass authentication and run arbitrary database commands. Organizations must verify patch status to maintain audit‑ready control assurance.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Hackers Actively Exploit Critical Roundcube SQL Injection (CVE‑2026‑48842)

What Happened – A pre‑authenticated SQL injection flaw (CVE‑2026‑48842) in Roundcube’s virtuser_query plugin was patched in May 2026, but the Canadian Centre for Cyber Security now confirms it is being actively exploited. The vulnerability lets an unauthenticated attacker bypass login, run arbitrary SQL commands, and exfiltrate the webmail database.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of un‑patched open‑source components that defeat authentication – a scenario continuous control‑assurance programs are built to detect and remediate.
  • Highlights the need for real‑time evidence that critical services are running approved, patched versions, supporting defensible audit trails.
  • Aligns with Verisq’s Access Controls capability: continuous verification that authentication mechanisms remain intact across the stack.

Who Is Affected – Providers of hosted email services, cPanel hosting operators, SaaS platforms that embed Roundcube, and any organization that runs the default Roundcube installation (technology, cloud‑infrastructure, and managed‑service sectors).

Recommended Actions

  • Verify your Roundcube version; upgrade immediately to 1.6.16 or 1.7.1.
  • If upgrade is not possible, disable or remove the virtuser_query plugin to close the attack surface.
  • Integrate automated patch‑validation checks into your continuous monitoring pipeline and retain evidence of compliance for audit readiness.

Technical Notes – The flaw is a pre‑authentication SQL injection in the virtuser_query plugin, allowing arbitrary database command execution without user interaction. No specific data type is disclosed, but the Roundcube database stores email headers, addresses, and potentially message bodies. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →