Roundcube Webmail flaw patched in May now actively exploited, Canadian cyber agency warns

Pre-authenticated SQL injection in virtuser_query plugin allows authentication bypass and database theft

By LineZotpaper
Published
Read Time2 min
The Canadian Centre for Cyber Security has warned that a high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks. The flaw, tracked as CVE-2026-48842, is a pre-authenticated SQL injection in the virtuser_query plugin that can let unprivileged attackers bypass authentication, execute malicious database commands and steal data from Roundcube databases.

Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel.

The Roundcube security team patched the flaw in May, describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses. Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction. Roundcube "strongly" recommended that users update to versions 1.6.16 and 1.7.1.

On Monday, four months after the patch was released, the Canadian Centre for Cyber Security updated its May advisory to warn that attackers are now actively exploiting the flaw. "Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild," the Cyber Center warned, urging administrators to secure their webmail servers. For administrators who cannot immediately upgrade, the agency recommends disabling or removing the virtuser_query plugin to eliminate the attack vector.

Threat monitoring non-profit Shadowserver now tracks over 523,000 Roundcube instances exposed on the Internet, though there is no information on how many are honeypots or have already been patched.

Roundcube security flaws have been a popular target for both cybercrime and state-backed hacking groups. The Winter Vivern (TA473) Russian threat group previously exploited a cross-site scripting zero-day (CVE-2023-5631) in attacks targeting European government entities, and the Russian APT28 cyber-espionage group abused multiple flaws to breach Ukrainian government email systems.

§

Analysis

Why This Matters

  • Roundcube is a widely deployed webmail interface — pre-installed with cPanel and serving millions of users — giving attackers a large pool of potential targets exposed to the internet.
  • The flaw allows unauthenticated attackers to bypass authentication and steal database contents, putting sensitive email data at risk without any user interaction.
  • The active exploitation warning comes four months after patches were released, suggesting many servers may still be running vulnerable versions.

Background

Roundcube is an open-source, browser-based email client widely used by hosting providers and organisations as their default webmail interface. Because it sits at the edge of email infrastructure and is exposed to the internet, it has become an attractive target for both financially motivated criminals and state-sponsored espionage groups. Previous campaigns by Russian threat actors — including Winter Vivern and APT28 — exploited Roundcube vulnerabilities to target European and Ukrainian government email systems. The current advisory is the latest in a pattern of webmail platforms becoming the focus of intrusion campaigns.

Key Perspectives

Roundcube security team: Patched CVE-2026-48842 in May and strongly recommended administrators update to versions 1.6.16 or 1.7.1. Canadian Centre for Cyber Security: Warns the vulnerability is being actively exploited in the wild and urges administrators to apply updates, or disable the virtuser_query plugin if upgrades are not immediately possible. System administrators: Face a significant patching burden — Shadowserver counts over 523,000 internet-exposed Roundcube instances, though it is unclear how many are honeypots or already patched. Security researchers and skeptics: Note the attack is described as high-complexity, which may restrict the range of actors able to exploit it, but the pre-authenticated, no-user-interaction nature of the flaw means the potential impact remains severe.

What to Watch

  • Whether other national cybersecurity agencies or vendors follow the Canadian Centre's advisory with warnings of their own.
  • The pace of exploitation reports and whether attacks broaden beyond initial targets into wider campaigns.
  • Whether administrators of exposed Roundcube instances patch to versions 1.6.16/1.7.1 or remove the virtuser_query plugin in the coming weeks.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.