Hackers attack Roundcube via SQL injection. It works before authorization and does not require user actions

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
534
Reaction score
951
Deposit
0$
A vulnerability can easily survive a fix if administrators do not have time to update the servers. This scenario is unfolding around Roundcube Webmail, where attackers already use a SQL injection that allows you to attack the mail system even before the user is authorized.





The Canadian Cyber Security Center on September 21 updated the May Bulletin on Roundcube and indicated that CVE-2026-48842 with a score of 8.1 on CVSS 3.1 are already operating in real attacks. The agency refers to reports from open sources, but does not yet reveal the purpose, extent of the campaign and the identity of the attackers.





The problem is in the built-in virtuser_query plugin, which matches usernames with email addresses through database requests. The reverse slash processing error allows the specially formed input to change the structure of the SQL request. The vulnerable code is triggered before checking the credentials through IMAP, so the attacker does not need a working account.





No action is required for exploitation on the part of the user, although CVSS evaluates the complexity of the attack as high. Successful SQL injection allows you to interfere with requests to the Roundcube database, bypass individual checks and receive the data stored there. We are talking about commands for the database, and not about direct execution of system commands on the server.










The developers of Roundcube closed CVE-2026-48842 on May 24 in versions 1.6.16 and 1.7.1. Vulnerable to 1.6.x branch up to 1.6.16 and branch 1.7.x to 1.7.1. At the time of the warning, more recent versions 1.6.19 and 1.7.4 are already available, so the developers advise updating the operating installations to current releases.





The scale of the potential attack surface remains large. Shadowserver tracks more than 523,000 Internet-accessible Roundcube installations. Such statistics do not show how many servers are really vulnerable, have already been updated or work as baits for attackers, so the number cannot be considered the number of real targets of CVE-2026-48842.





Roundcube regularly comes into the field of cybercriminals and cyberspy groups. In February 2026, two other vulnerabilities of the platform have already been used in real-world attacks. It was about CVE-2025-49113 with a score of 9.9 on CVSS 3.1 and CVE-2025-68461 with a score of 7.2 on CVSS 3.1.





In the summer, the vulnerable servers Roundcube again became the target of a cyber-espionage campaign. China-related activity UNK_MassTraction attacked universities in the United States and Canada, using several webmail errors to steal credentials and secure on servers. This interest makes long-outstanding installations particularly attractive goals.





Administrators are advised to install the current version of Roundcube. If it is not possible to quickly update the server, the Canadian center and publications on the vulnerability are advised to disable or completely remove the virtuser_query, since it is through the plugin that the vulnerable path goes. The correction has been around for four months, but the advent of confirmed exploitation turns delayed renewal from a potential risk into a practical threat.
 
Top Bottom