Vulnerabilities & Exploits · Web App Attack

Roundcube Flaw Turns Mail Logins Into Server Control

The Canadian Centre for Cyber Security says Roundcube Webmail flaw CVE-2025-49113 is being exploited in the wild, turning a May patch into an active intrusion path for internet-facing mail systems. The issue affects logged-in users of Roundcube 1.5.x and 1.6.x, with fixed releases now available in 1.5.10 and 1.6.11+.

The bug sits in how Roundcube handles trusted session input: a crafted value in a message or link path can slip past validation, so a signed-in user can trigger code execution on the mail server itself. That means the problem is not mailbox viewing alone; if attackers reach a valid account, they may be able to move from email access to server-level control.

For organizations that expose Roundcube to the internet, the lasting risk is compromised credentials, not just a vulnerable web app. If a mail host accepts user logins from weak or stolen passwords, the session can become the foothold for full compromise even after the patch is applied.

1 source · 13h ago

CVE-2025-49113

NVD KEV

Known exploited · CISA KEV

CVSS 9.9 CRITICAL: roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because… EPSS 99% (100th percentile).

CISA federal remediation date Mar 13 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-09-24

Every edition of this story: Roundcube Flaw Turns Mail Logins Into Server Control

More from today