Roundcube SQL injection flaw now exploited in attacks
Attackers are exploiting a high-severity SQL injection vulnerability in Roundcube Webmail that was patched in May, according to the Canadian Centre for Cyber Security.
The flaw, tracked as CVE-2026-48842, sits in virtuser_query, a plugin that ships with Roundcube. The plugin handles user lookups against a database and maps users to their email addresses. The Roundcube security team described the bug as a pre-authenticated SQL injection, which means an attacker does not need to log in to reach it.
Roundcube Webmail is an open-source, browser-based email client that talks to mail servers over IMAP. Thousands of services use it as their default mail interface, and it has millions of users. It also comes pre-installed with cPanel, a popular control panel that hosting providers give customers to manage websites and email.
Sponsored Recommended for you – discover more →
