Attackers Need No Login to Exploit This Roundcube Plugin
Roundcube released the fix on 24 May. Four months later, Canada’s Cyber Centre says the vulnerable path is being exploited in the wild.
The issue, CVE-2026-48842, is a pre-authentication SQL injection in Roundcube’s virtuser_query plugin. An attacker does not need an account or user interaction, but the vulnerable plugin and its database-backed lookup path must be in use.
The plugin condition matters
Roundcube’s May security release describes the flaw as a backslash-escape bypass in a preg_replace operation used by the virtuser_query plugin. That plugin maps virtual usernames to mailbox addresses through database queries.
Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1 are affected. The fixed versions are 1.6.16 and 1.7.1, although operators should normally move to the newest supported security release rather than stopping at the first fixed build.
The vulnerability has a high-complexity attack vector. That reduces reliability compared with a simple one-request exploit, but it does not add authentication or user interaction. High complexity is not a reason to leave an internet-facing mail system vulnerable after exploitation has been reported.
The exploitation warning is real, but sparse
The Canadian Centre for Cyber Security updated its advisory on 21 September to say open-source reporting indicates that CVE-2026-48842 is being exploited in the wild.
The advisory does not identify an actor, victim, exploitation volume or observed payload. It also does not say that every exposed Roundcube server is vulnerable. BleepingComputer reported that Shadowserver tracks more than 523,000 internet-exposed Roundcube instances, but the number does not distinguish patched systems, honeypots or deployments that do not use the affected plugin.
Patch, then investigate the vulnerable period
- Identify every Roundcube deployment. Include hosting panels, managed mail platforms, legacy customer portals and disaster-recovery systems.
- Confirm the running version. Upgrade affected 1.6.x and 1.7.x branches to the newest supported release. Do not rely on package-download dates.
- Check whether
virtuser_queryis enabled. If an emergency upgrade cannot happen immediately, disabling or removing that plugin can remove this specific path, but only after confirming the operational effect. - Preserve relevant evidence. Retain web, application, authentication and database logs from the vulnerable period before normal rotation removes them.
- Review unexplained database and account activity. Look for anomalous queries, authentication bypass indicators, changed mappings, unexpected administrative behaviour and follow-on access.
- Separate patching from assurance. Installing the update closes the known path. It does not establish whether the server was touched before the fix.
BlackTree previously covered a different email-related hosting control path that could reach root. This Roundcube issue is not the same vulnerability, but it reinforces why hosted mail components deserve their own inventory and evidence plan rather than being treated as invisible parts of a control panel.
The patch was available before the current exploitation warning. The decision now is not whether the issue is new. It is whether the organisation can prove that the vulnerable plugin is gone and that the earlier exposure has been examined.
Sources
- Roundcube, security releases 1.6.16 and 1.7.1, published 24 May 2026. The page provides no publication time.
- Canadian Centre for Cyber Security, advisory AV26-503, first dated 25 May 2026 and updated 21 September 2026. The page provides no publication or update times.
- BleepingComputer, exploitation reporting, published 24 September 2026 at 09:27 as displayed. The page does not label the timezone.


