CVE-2026-48846
An attacker can exploit multiple vulnerabilities in Roundcube Webmail to conduct SQL injection attacks, bypass security measures, manipulate data, disclose confidential information, gain elevated privileges, execute arbitrary code, or conduct cross-site scripting attacks.
CSIRTS triage
- What
- Multiple vulnerabilities can lead to SQL injection, security bypass, data manipulation, information disclosure, privilege escalation, and arbitrary code execution.
- Who is affected
- Attackers targeting Roundcube Webmail installations.
- Urgency
- High urgency due to the variety of critical vulnerabilities that can be exploited.
- Action
- Apply available patches to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-48846
Get an email if CVE-2026-48846 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
Advisory coverage (1)
- high[UPDATE] [high] Roundcube Webmail: Multiple vulnerabilitiescert-bund · 2026-07-22
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-48846)