logo

Critical Roundcube Flaw Allows Attackers to Inject SQL Queries

ID: 5bed5523-bca8-53cc-8b4d-85cc3eb5317e

STIX ID: report--5bed5523-bca8-53cc-8b4d-85cc3eb5317e

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Lucas Martin

...
...

Roundcube Webmail released security updates (1.6.16 and 1.7.1) addressing eight vulnerabilities — most critically a pre-authentication SQL injection in the virtuser_query plugin that can execute arbitrary database queries without credentials and an LDAP autovalues code-evaluation flaw that could enable remote code execution; additional issues include XSS, CSS injection, SSRF bypasses, session poisoning enabling file deletion, and remote resource blocking bypasses. Administrators of internet-facing Roundcube instances should patch immediately, consider disabling the virtuser_query plugin if unused, audit logs for anomalous queries or sessions, and review LDAP settings to mitigate potential multi-stage exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.