Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Chronological Source Flow
Back

AI Fusion Summary

The Canadian Centre for Cyber Security reports active exploitation of CVE-2026-48842, a high-severity pre-authentication SQL injection in Roundcube Webmail. Affecting versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the flaw resides in the virtuser_query plugin due to a preg_replace() issue. With a CVSS v3.1 score of 8.1, the vulnerability depends on specific configurations. While active exploitation is confirmed, public reports have not yet verified individual data theft or OS command execution within the affected systems.
Community Comments
Loading updates...
0