Critical SQL Injection and XSS Vulnerabilities in RoundcubeMail Affect Fedora Users

Critical SQL Injection and XSS Vulnerabilities in RoundcubeMail Affect Fedora Users

4 Jun 2026 Linuxsecurity 73% similarity 74.0
Share:

Article Content

Browse articles
ThreatCluster

Recent updates to RoundcubeMail for Fedora 43 and 44 revealed critical vulnerabilities, including SQL injection and cross-site scripting (XSS) issues. CVE-2026-48842 details a pre-auth SQL injection in the virtuser_query plugin, while CVE-2026-48843 highlights insufficient CSS sanitization leading to information disclosure and server-side request forgery (SSRF). Other vulnerabilities include privilege escalation and code injection risks, with multiple CVEs published on May 25, 2026. Users of Fedora 43 and 44 are urged to apply the latest updates to mitigate these risks. The vulnerabilities could allow attackers to exploit email systems, potentially leading to unauthorized access and data breaches. The updates can be installed via the 'dnf' package manager. Security teams should prioritize patching to protect their systems from these vulnerabilities.

Key Points: • Critical vulnerabilities in RoundcubeMail affect Fedora 43 and 44 users. • CVE-2026-48842 and CVE-2026-48843 involve SQL injection and XSS issues. • Immediate patching is recommended to prevent potential exploitation.

ThreatCluster AI

Timeline

2026-05-25
Multiple CVEs published for RoundcubeMail
CVE-2026-48842, CVE-2026-48843, CVE-2026-48844, CVE-2026-48845, and CVE-2026-48848 were published, detailing critical vulnerabilities affecting RoundcubeMail.
Linuxsecurity
2026-05-25
CVE-2026-48842 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-25
CVE-2026-48843 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-25
CVE-2026-48845 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-25
CVE-2026-48844 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-25
CVE-2026-48848 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-03
Fedora 44 RoundcubeMail update released
An update to RoundcubeMail 1.7.1 was released to address critical SQL injection and XSS vulnerabilities.
Linuxsecurity
2026-06-04
Fedora 43 RoundcubeMail update released
An update to RoundcubeMail 1.6.16 was released to fix critical vulnerabilities, including SQL injection and XSS issues.
Linuxsecurity

Community

Browse all →