Skip to finding
important · Zero-click — Webmail

Attackers are exploiting Roundcube’s pre-authentication SQL injection.

Affects

Roundcube Webmail, a self-hosted browser-based email client commonly deployed on Linux hosting servers.

The exposed population is limited to installations using the optional virtuser_query plugin. There, a backslash-escape bypass lets login input reach SQL before authentication, enabling database commands, authentication bypass or access to Roundcube records.

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 25, 2026