Code Defence Cyber security

Roundcube Webmail pre-auth SQL injection vulnerability CVE-2026-48842 actively exploited in the wild

National cyber security advisories have issued alerts confirming active wild exploitation targeting a high-severity SQL injection vulnerability in a widely used open-source webmail portal. Unauthenticated remote actors transmit malformed database queries to extract sensitive user authentication hashes and active session cookies.

The vulnerability, tracked as CVE-2026-48842 with a CVSS score of 8.1, impacts Roundcube Webmail releases 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1. The defect resides within the virtuser_query plugin processing user lookup routines. Unauthenticated remote adversaries transmit crafted HTTP requests containing SQL injection vectors to force the underlying database engine to dump account password hashes, session tokens, and cleartext email records.

Subverting webmail portals grants threat actors unmonitored access to corporate communications and identity verification channels. Possessing webmail session tokens or account credentials allows adversaries to conduct internal phishing, bypass multi-factor authentication resets, and harvest sensitive corporate data files.

– Upgrade Roundcube Webmail installations immediately to security maintenance release builds 1.6.16 or 1.7.1 or higher.

– Disable the virtuser_query plugin temporarily if immediate software upgrade workflows cannot be executed.

– Inspect webmail server database query logs for anomalous SQL syntax or unauthorized session table dump attempts.

– Enforce mandatory password resets and invalidate active webmail session cookies for accounts accessed during intrusion windows.

Webmail portal resilience relies on rigid SQL query parameterization and prompt security patch deployment to ensure messaging infrastructure remains insulated from unauthenticated database manipulation. #CodeDefence #Roundcube #Webmail #SQLi #EmailSecurity #AppSec #PatchManagement #ThreatIntelligence
/

Scroll to Top