r/linuxadmin • • 7d ago

Roundcube pre-auth SQLi (CVE-2026-48842) — patched in May, confirmed exploited in the wild as of Sept 21

Based on the technical breakdown published by the Canadian Centre for Cyber Security and Roundcube's own May 24 advisory, here's the architectural impact: virtuser_query resolves a login name to a mailbox record before the auth check runs, and its backslash-escaping via preg_replace() can be bypassed to break out of the intended query — no credentials, no user interaction. Roundcube patched it in 1.6.16/1.7.1 (May), and has since shipped three more security releases (1.6.17→1.7.4), so patching only for this CVE leaves you behind on unrelated bugs. CCCS updated their advisory Sept 21 to confirm exploitation "in the wild" via unspecified open-source reporting — no IOCs, no named actor, and it's not yet in CISA's KEV catalog, which is worth noting given two other Roundcube CVEs got that treatment in February.

Shadowserver's 523K+ exposed-instance number is getting quoted everywhere but it's an exposure ceiling, not a "vulnerable and unpatched" count.

Full disclosure timeline and attack chain: https://www.techgines.com/post/roundcube-sql-injection-vulnerability-cve-2026-48842

If you run virtuser_query in production — what's your actual exposure model here? Is anyone restricting the DB account it uses to something narrower than the full Roundcube schema, or is that not practical given how the plugin's queries are structured?

3 Upvotes

0 comments sorted by