CVE-2026-48842

NameCVE-2026-48842
DescriptionRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4604-1, DSA-6301-1
Debian Bugs1137507

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
roundcube (PTS)bullseye1.4.15+dfsg.1-1+deb11u4vulnerable
bullseye (security)1.4.15+dfsg.1-1+deb11u9fixed
bookworm1.6.5+dfsg-1+deb12u8vulnerable
bookworm (security)1.6.5+dfsg-1+deb12u9fixed
trixie1.6.15+dfsg-0+deb13u1vulnerable
trixie (security)1.6.16+dfsg-0+deb13u1fixed
forky, sid1.6.16+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
roundcubesourcebullseye1.4.15+dfsg.1-1+deb11u9DLA-4604-1
roundcubesourcebookworm1.6.5+dfsg-1+deb12u9DSA-6301-1
roundcubesourcetrixie1.6.16+dfsg-0+deb13u1DSA-6301-1
roundcubesource(unstable)1.6.16+dfsg-11137507

Notes

https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
https://github.com/roundcube/roundcubemail/commit/87124cc7136a48b5fa9d2b40dfead6e9dcaeaf4b

Search for package or bug name: Reporting problems