CVE-2026-48842

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

  • Published May 25, 2026
  • CVSS 8.1 high
  • 0.9% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

In the news

CVE-2026-48842 at the National Vulnerability Database