Skip to content
Exploit for CVE-2026

Exploit for CVE-2026

Sploitus • September 25, 2026

Python 3 checker for **[CVE-2026-48842]( in **Roundcube Webmail** (optional `virtuser_query` plugin).

This PoC is listed on **[PoCbit]( — [CVE-2026-48842 on pocbit.org](

Running the PoC prints a **PoCbit** header; JSONL lines include `pocbit` / `pocbit_page`.

| **Product** | [Roundcube Webmail]( |

| **Component** | Built-in plugin `virtuser_query` (DB user/email/host lookup) |

| **Affected** | **1.6.x escape(...), ...)`**. PHP interprets backslashes in the **replacement** string, undoing SQL escaping — **pre-auth SQL injection** ([fix: use `str_replace`](

Advisory: [Roundcube security updates 2026-05-24](

# Detect Roundcube + version + virtuser plugin file

python poc.py -u --json

# Active SQLi probe (SLEEP / error heuristics on login POST)

python poc.py -u --verify

python poc.py --list targets.example.txt --threads 20 --quiet

python poc.py --list targets.example.txt --verify --sqli-delay 5

- **Exploitability requires `virtuser_query` enabled** on the server (not default on all installs). PoC flags plugin PHP path when reachable.

- `--verify` sends crafted `_user` values to `?_task=login` (no valid password needed for injection attempt).

- Mitigation: upgrade to **≥ 1.6.16 / 1.7.1**, or remove `virtuser_query` from `$config['plugins']`.

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Domains (1)

Platforms (1)

Tools (1)