Users should upgrade Roundcube Webmail to version 1.6.16 or 1.7.1 immediately to apply the fix for CVE-2026-48842. If immediate upgrading is not possible, consider disabling the virtuser_query plugin or implementing network controls to limit exposure. Monitor for patches from Roundcube developers and apply them as soon as possible.
Quick answers
What is CVE-2026-48842?
Users should upgrade Roundcube Webmail to version 1.6.16 or 1.7.1 immediately to apply the fix for CVE-2026-48842. If immediate upgrading is not possible, consider disabling the virtuser_query plugin or implementing network controls to limit exposure. Monitor for patches from Roundcube developers and apply them as soon as possible.
How severe is CVE-2026-48842?
critical, CVSS 8.1
Is CVE-2026-48842 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-48842 be mitigated?
Users should upgrade Roundcube Webmail to version 1.6.16 or 1.7.1 immediately to apply the fix for CVE-2026-48842. If immediate upgrading is not possible, consider disabling the virtuser_query plugin or implementing network controls to limit exposure. Monitor for patches from Roundcube developers and apply them as soon as possible.
CVSS
8.1
Vendor
Roundcube
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Roundcube Webmail
Mitigation
Users should upgrade Roundcube Webmail to version 1.6.16 or 1.7.1 immediately to apply the fix for CVE-2026-48842. If immediate upgrading is not possible, consider disabling the virtuser_query plugin or implementing network controls to limit exposure. Monitor for patches from Roundcube developers and apply them as soon as possible.
The Canadian Centre for Cyber Security has issued a warning regarding a pre-authentication SQL injection vulnerability in Roundcube Webmail that is being actively exploited in the wild. The flaw, tracked as CVE-2026-48842, has a CVSS score of 8.1 and affects the virtuser_query plugin in versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. Successful exploitation could allow remote attackers to execute arbitrary SQL commands, potentially leading to data exfiltration, modification, or denial of service. Users are strongly advised to upgrade to the patched versions immediately.