Junglewise Threat Intelligence

CVE-2026-48844: Roundcube Webmail code injection in LDAP autovalues option

CVE-2026-48844 · Severity: high · CVSS 7.5 · Published 2026-05-25

Technologies: Roundcube Webmail. Vendors: Roundcube.

Executive brief

Roundcube Webmail, a widely used open-source web-based email client, contains a security vulnerability in its LDAP address book integration. An attacker with low-level access could exploit insecure code evaluation logic to execute unauthorized commands on the server. This could lead to a full system compromise, unauthorized access to sensitive emails, or disruption of mail services.

Technical details

A code injection vulnerability exists in Roundcube Webmail's LDAP implementation due to insecure code evaluation logic within the 'autovalues' option. The flaw allows an authenticated attacker with network access to trigger the execution of arbitrary code by exploiting how the application processes LDAP configuration values. The vulnerability is rooted in the use of eval-like logic for dynamic value generation. Roundcube has addressed this by completely removing support for code evaluation in the LDAP autovalues option in versions 1.6.16 and 1.7.1. Exploitation requires the attacker to have at least low-privileged credentials (PR:L) and depends on specific LDAP configurations (AC:H).

Affected products

  • Roundcube Webmail 1.6.x before 1.6.16, 1.7.x before 1.7.1

Timeline

  • 2026-05-24: patched: Versions 1.6.16 and 1.7.1 released.
  • 2026-05-24: advisory: Vendor security advisory published.
  • 2026-05-25: disclosed: CVE-2026-48844 published.

References

Related threats