Description
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)
In plain language
AI Worth attentionIf you run RoundCube Webmail, older versions (1.6.x before 1.6.16 and 1.7.x before 1.7.1) can be tricked into unsafe “code evaluation” for the LDAP autovalues setting, which may allow an attacker to inject code—fix soon, especially if your webmail is reachable from the internet.
In RoundCube Webmail, insecure code evaluation logic tied to the LDAP “autovalues” option can permit code injection in versions 1.6.x < 1.6.16 and 1.7.x < 1.7.1; the vendor removed support for code evaluation in the fixed releases (1.6.16 and 1.7.1).
What to do now
- Check your RoundCube Webmail version and whether you are using LDAP autovalues/code-evaluation features.
- Compare your version to the fixed releases: update 1.6.x to 1.6.16 or later, or update 1.7.x to 1.7.1 or later.
- If you can’t upgrade immediately, disable LDAP-related autovalues/code-evaluation usage (or align with the vendor’s remediation guidance) until you patch.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-48844 and every CVE in our database. Create a free account — no credit card required.
Create Free Account