{"id":"CVE-2026-48842","title":"Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.","summary":"Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-89"],"vendor":"Roundcube","product":"Webmail","affected":["Webmail >= 1.6.0 < 1.6.16","Webmail >= 1.7.0 < 1.7.1"],"published":"2026-05-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T04:17:35.357","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48842","references":[{"url":"https://github.com/roundcube/roundcubemail/commit/3406183a9976e36f992d3468f37d0e2346526ee9","label":"cve@mitre.org"},{"url":"https://github.com/roundcube/roundcubemail/commit/87124cc7136a48b5fa9d2b40dfead6e9dcaeaf4b","label":"cve@mitre.org"},{"url":"https://github.com/roundcube/roundcubemail/releases/tag/1.6.16","label":"cve@mitre.org"},{"url":"https://github.com/roundcube/roundcubemail/releases/tag/1.7.1","label":"cve@mitre.org"},{"url":"https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/06/03/17","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-24T00:00:00+00:00"},"epss":0.00888,"epssPercentile":0.57555,"ingestedAt":"2026-09-25T03:58:52.652Z","slug":"CVE-2026-48842","body":"## Overview\n\nRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}