Roundcube Webmail SQL Injection Bug Exploited Before Patch

Canada's cyber security center warned that attackers are actively exploiting a patched Roundcube Webmail flaw. The vulnerability, CVE-2026-48842, is a pre-authentication SQL injection in the virtuser_query plugin with a CVSS score of 8.1. It affects versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Canada’s cyber security center has warned that the Roundcube Webmail vulnerability CVE-2026-48842 was being exploited by attackers. The issue is a pre-authentication SQL injection in the virtuser_query plugin, and it carries a CVSS score of 8.1.
The affected releases are Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1. A patch exists, but exploitation occurred before it was available, according to the warning.
Organizations and individuals using affected Roundcube Webmail versions could be exposed if systems remain unpatched. Because the flaw is pre-authentication, attackers may reach the vulnerable plugin without valid credentials, potentially compromising email-related data or service integrity. Administrators may need to prioritize updates, while users could face reduced trust in webmail communications if exploitation succeeds. The warning highlights how quickly known flaws can be weaponized before defenses are applied.