important · Zero-click — Webmail
Attackers are exploiting Roundcube’s pre-authentication SQL injection.
Affects
Roundcube Webmail, a self-hosted browser-based email client commonly deployed on Linux hosting servers.
The exposed population is limited to installations using the optional virtuser_query plugin. There, a backslash-escape bypass lets login input reach SQL before authentication, enabling database commands, authentication bypass or access to Roundcube records.
Detail and 4 sources
Roundcube has published fixed releases.
Sources
ResearchSecurity updates 1.6.16 and 1.7.1 releasedResearchLa faille SQL de Roundcube est désormais exploitée en conditions réelles, quatre mois après son correctif — ETTAYEBVendorHackers now exploit critical Roundcube flaw in code injection attacksSecondaryRoundcube security advisory (AV26-503) – Update 1