{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-25T16:07:31.837","vulnerabilities":[{"cve":{"id":"CVE-2026-48842","sourceIdentifier":"cve@mitre.org","published":"2026-05-25T20:16:36.630","lastModified":"2026-09-25T04:17:35.357","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass."},{"lang":"es","value":"Roundcube Webmail 1.6.x anterior a 1.6.16 y 1.7.x anterior a 1.7.1 tiene una inyección SQL de preautenticación en el plugin virtuser_query mediante un bypass de escape de barra invertida de preg_replace()."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"Roundcube","product":"Webmail","defaultStatus":"unaffected","versions":[{"version":"1.6.0","lessThan":"1.6.16","versionType":"semver","status":"affected"},{"version":"1.7.0","lessThan":"1.7.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-24T00:00:00+00:00","id":"CVE-2026-48842","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://github.com/roundcube/roundcubemail/commit/3406183a9976e36f992d3468f37d0e2346526ee9","source":"cve@mitre.org"},{"url":"https://github.com/roundcube/roundcubemail/commit/87124cc7136a48b5fa9d2b40dfead6e9dcaeaf4b","source":"cve@mitre.org"},{"url":"https://github.com/roundcube/roundcubemail/releases/tag/1.6.16","source":"cve@mitre.org"},{"url":"https://github.com/roundcube/roundcubemail/releases/tag/1.7.1","source":"cve@mitre.org"},{"url":"https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1","source":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/06/03/17","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}