Python 3 checker for **[CVE-2026-48842]( in **Roundcube Webmail** (optional `virtuser_query` plugin).
This PoC is listed on **[PoCbit]( — [CVE-2026-48842 on pocbit.org](
Running the PoC prints a **PoCbit** header; JSONL lines include `pocbit` / `pocbit_page`.
| **Product** | [Roundcube Webmail]( |
| **Component** | Built-in plugin `virtuser_query` (DB user/email/host lookup) |
| **Affected** | **1.6.x escape(...), ...)`**. PHP interprets backslashes in the **replacement** string, undoing SQL escaping — **pre-auth SQL injection** ([fix: use `str_replace`](
Advisory: [Roundcube security updates 2026-05-24](
# Detect Roundcube + version + virtuser plugin file
python poc.py -u --json
# Active SQLi probe (SLEEP / error heuristics on login POST)
python poc.py -u --verify
python poc.py --list targets.example.txt --threads 20 --quiet
python poc.py --list targets.example.txt --verify --sqli-delay 5
- **Exploitability requires `virtuser_query` enabled** on the server (not default on all installs). PoC flags plugin PHP path when reachable.
- `--verify` sends crafted `_user` values to `?_task=login` (no valid password needed for injection attempt).
- Mitigation: upgrade to **≥ 1.6.16 / 1.7.1**, or remove `virtuser_query` from `$config['plugins']`.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
