SECURITY·중요도 9·2026. 09. 25.·The Hacker News

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

── KO ──────────────────

Roundcube 웹메일에서 발견된 SQL 주입 취약점이 악용되고 있다고 경고합니다.

캐나다 사이버 보안 센터는 Roundcube 웹메일의 패치된 취약점이 실제로 악용되고 있다고 경고했습니다. 이 취약점(CVE-2026-48842)은 1.6.x 버전 1.6.16 이전과 1.7.x 버전 1.7.1 이전의 virtuser_query 플러그인에서 발견된 사전 인증 SQL 주입 문제로, CVSS 점수는 8.1입니다. 이 문제는 preg_replace() 함수의 백슬래시와 관련이 있습니다.


── EN ──────────────────

A SQL injection flaw in Roundcube Webmail is actively being exploited.

The Canadian Centre for Cyber Security has issued a warning about an actively exploited vulnerability in Roundcube Webmail. The vulnerability, identified as CVE-2026-48842, is a pre-authentication SQL injection in the virtuser_query plugin affecting versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, with a CVSS score of 8.1. The issue arises from a backslash in the preg_replace() function.

원문 보기 →목록으로