Threat actors are exploiting a high-severity Roundcube flaw, tracked as CVE-2026-48842, which enables unauthenticated SQL injection through the virtuser_query plugin. Successful attacks can expose messages, address books, user identities, and other sensitive database content, prompting Roundcube to release fixes in versions 1.6.16 and 1.7.1. #Roundcube #CVE-2026-48842 #virtuser_query
Keypoints
- CVE-2026-48842 is a high-severity SQL injection flaw in Roundcube.
- The virtuser_query plugin can be abused without authentication.
- Attackers bypass backslash-based filtering with crafted queries.
- Exploitation may expose messages, address books, and user identities.
- Roundcube fixed the issue in versions 1.6.16 and 1.7.1.
Read More: https://www.securityweek.com/roundcube-webmail-vulnerability-in-attackers-crosshairs/