Name CVE-2026-48842 Description Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. Source CVE (at NVD ; CERT , ENISA , LWN , oss-sec , fulldisc , Debian ELTS , Red Hat , Ubuntu , Gentoo , SUSE bugzilla /CVE , GitHub advisories /code /issues , web search , more )References DLA-4604-1 , DSA-6301-1 Debian Bugs 1137507
Vulnerable and fixed packages The table below lists information on source packages.
Source Package Release Version Status roundcube (PTS )bullseye 1.4.15+dfsg.1-1+deb11u4 vulnerable bullseye (security) 1.4.15+dfsg.1-1+deb11u9 fixed bookworm 1.6.5+dfsg-1+deb12u8 vulnerable bookworm (security) 1.6.5+dfsg-1+deb12u9 fixed trixie 1.6.15+dfsg-0+deb13u1 vulnerable trixie (security) 1.6.16+dfsg-0+deb13u1 fixed forky, sid 1.6.16+dfsg-1 fixed
The information below is based on the following data on fixed versions.
Notes https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1 https://github.com/roundcube/roundcubemail/commit/87124cc7136a48b5fa9d2b40dfead6e9dcaeaf4b