Roundcube Pre-Auth SQL Injection Now Under Active Attack
Security / news
Roundcube Pre-Auth SQL Injection Now Under Active Attack
Roundcube shipped a fix four months before Canada's Cyber Centre confirmed exploitation, and more than 523,000 servers are still reachable from the internet.
An unauthenticated attacker can rewrite the database query Roundcube runs during login and read or alter webmail data on any server running the virtuser_query plugin with a vulnerable lookup configured, and Canada's Centre for Cyber Security said Sept. 21 that attackers are doing exactly that against CVE-2026-48842.
Roundcube shipped the fix in versions 1.6.16 and 1.7.1 on May 24, 2026, describing it in its own release notes as a fix for "pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass, reported by skull." The bug carries a CVSS v3.1 score of 8.1, according to The Hacker News, with no privileges or user interaction required to trigger it.
Why the fix took four months to matter
The flaw is pre-authentication, meaning it fires during the login flow itself rather than after a session exists, but it is not universal to every Roundcube install. Two conditions have to hold: the virtuser_query plugin has to be loaded in the server's configuration, and the plugin's lookup query has to be one of the vulnerable patterns. A default Roundcube installation, which does not enable virtuser_query, is not exposed. That narrower blast radius is likely why four months passed between the May patch and the first confirmed exploitation.
How the bypass works
The plugin maps login names to email addresses through a database query, and it uses PHP's preg_replace function to escape characters an attacker could use to break out of that query. According to a technical writeup from Hive Security, the escaping rule itself can be bypassed with a crafted backslash sequence, letting an attacker's input reach the database with its SQL meaning intact before Roundcube has verified any credentials.
What happens after the injection
"Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne said, as quoted by The Hacker News, which reported that observed intrusions have gone on to deploy web shells or a post-exploitation tool called VShell. Roundcube has drawn nation-state interest before: SentinelOne has separately tracked a China-aligned group it calls UNK_MassTraction exploiting a different Roundcube flaw in July 2026.
| Branch | Vulnerable before | Patched | Current recommended |
|---|---|---|---|
| 1.6.x (LTS) | 1.6.16 | 1.6.16 (May 24) | 1.6.19 (Sept. 6) |
| 1.7.x | 1.7.1 | 1.7.1 (May 24) | 1.7.4 (Sept. 6) |
Shadowserver counted 523,000 Roundcube instances exposed to the internet as of Sept. 23, according to The Hacker News, though it has not published how many of those are already patched or configured without the vulnerable plugin.
The same disclosure-to-exploitation gap shows up in CISA's Sept. 25 addition of a Microsoft SharePoint flaw, where the fix and the public warning were separated by weeks, and in a vendor that has stayed silent on 14 disclosed camera bugs; in both cases, as here, the gap that mattered was not the patch itself but how long it took anyone to say publicly that the patch was needed.
What to do now
Administrators running 1.6.x before 1.6.19 or 1.7.x before 1.7.4 should upgrade immediately. Anyone who cannot upgrade right away should check whether virtuser_query is loaded in their configuration and disable it if so; Roundcube's own advisory frames this as a full workaround, since the plugin's absence removes the vulnerable code path entirely rather than just reducing exposure to it.
Sources
More in Security
- 01Pwn2Own Ireland 2026 Day One: Seven of 20 Listed Entries Were Collisions, and OpenAI Codex Fell to Argument InjectionSamsung's Galaxy S26 was hit three times, Sonos and Philips Hue each twice or more, and a Google Pixel 10 attempt ran out of time. Vendors get 90 days before details go public.
- 02Atlassian CVE-2026-21589: A 9.3 File-Access Flaw Hits Every Data Center Version of Eight ProductsAn unauthenticated request can read a file from the web root if the attacker already knows its exact path. Atlassian reports no exploitation and has released fixes for each product line.
- 03WordPress CVE-2026-87902: A Page-Template Bug in Every Release Since 4.7, Patched in 7.1.2The 9.2 rating describes a file include; code execution needs a theme folder starting with page- and a PHP setting, but probes began five hours after the patch.
- 04Citrix's September 27 NetScaler Fix Does Not Cover CVE-2026-88779, Now on CISA's Exploited ListBuilds that closed two exploited zero-days stay vulnerable to a SAML flaw that CISA added on October 4 with a three-day deadline.