๐Ÿ” CVE Alert

CVE-2026-48842

HIGH 8.1
CVSS Score
8.1
EPSS Score
0.1%
EPSS Percentile
28th

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

CWE CWE-89
Vendor roundcube
Product webmail
Published May 25, 2026
Last Updated Jun 3, 2026
Stay Ahead of the Next One

Get instant alerts for roundcube webmail

Be the first to know when new high vulnerabilities affecting roundcube webmail are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Roundcube / Webmail
1.6.0 < 1.6.16 1.7.0 < 1.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
roundcube.net: https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1 github.com: https://github.com/roundcube/roundcubemail/releases/tag/1.7.1 github.com: https://github.com/roundcube/roundcubemail/commit/3406183a9976e36f992d3468f37d0e2346526ee9 github.com: https://github.com/roundcube/roundcubemail/releases/tag/1.6.16 github.com: https://github.com/roundcube/roundcubemail/commit/87124cc7136a48b5fa9d2b40dfead6e9dcaeaf4b openwall.com: http://www.openwall.com/lists/oss-security/2026/06/03/17