Ottawa says the May Roundcube patch is being used. Four months is long enough.
Vulnerability Management

Ottawa says the May Roundcube patch is being used. Four months is long enough.

Mathew Potter

Security Analyst

September 24, 2026

The Canadian Centre for Cyber Security updated a May note and said the Roundcube hole is being used. BleepingComputer carried it this morning. CVE-2026-48842 is a pre-authentication SQL injection in the virtuser_query plugin, the piece that maps users to mailboxes from a database. No login. No click. Roundcube patched it in May: 1.6.16 and 1.7.1. Four months later, Ottawa is telling administrators to finish the job. If you cannot update today, they say disable or remove that plugin. That is the workaround. The update is the close.

What virtuser_query actually is

A lot of small hosts and professional offices run Roundcube because it came with the cPanel or the mail appliance. virtuser_query is how some of those boxes look up who owns an address. The May advisory called the hole high complexity and still scored it 8.1. Successful use, in that write-up, is database commands and a path to data in Roundcube's own tables. We are not going to walk the query. The useful facts are the versions and the plugin name.

The Cyber Centre's original AV26-503 landed May 25. Monday's update is the sentence that matters: open-source reporting says it is exploited in the wild. That is not a new CVE. It is a May patch that shops filed under "later."

Why this is a Canadian mail problem

Roundcube sits behind a lot of @company.ca inboxes that never got a product name in the IT inventory. The site is WordPress. The panel is cPanel. The webmail is "the round login page." If that page is still on 1.6.15 or 1.7.0, you are on the May list with a September stamp. Pair that with yesterday's CalDAV-to-root on the same shared box and you have two ways a customer login, or no login at all, becomes the host.

What we would do today

  • Write the Roundcube version. 1.6.x goes to 1.6.16 or later. 1.7.x goes to 1.7.1 or later. If you cannot do that this morning, turn off or remove virtuser_query until you can.
  • If the webmail is internet-facing and unpatched since May, treat it as possibly touched. Review accounts, filters, and identities you did not create.
  • Do not fetch a public test. The CCC note is enough.
  • If the same machine is cPanel, finish 11.134.0.57 / 11.136.0.41 / 11.138.0.8 and Toolkit 6.11.3. Mail and calendars on one box is the week.

Bottom line

A May webmail patch that Ottawa had to mention again in September is still a September job if you have not applied it. Forensic Five reviews the page people actually use to read mail, not only the firewall in front of it. From St. Albert, Alberta. Update Roundcube. Then go look at WordPress 7.1.2 and the TeamCity box, because those two are being used for worse than a mailbox.

Tags

Roundcube CVE-2026-48842 Canadian Cyber Centre webmail

Share This Article

About the Author

Mathew Potter

Security Analyst

Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.