Roundcube Flaw Turns Mail Logins Into Server Control
The Canadian Centre for Cyber Security says Roundcube Webmail flaw CVE-2025-49113 is being exploited in the wild, turning a May patch into an active intrusion path for internet-facing mail systems. The issue affects logged-in users of Roundcube 1.5.x and 1.6.x, with fixed releases now available in 1.5.10 and 1.6.11+.
The bug sits in how Roundcube handles trusted session input: a crafted value in a message or link path can slip past validation, so a signed-in user can trigger code execution on the mail server itself. That means the problem is not mailbox viewing alone; if attackers reach a valid account, they may be able to move from email access to server-level control.
For organizations that expose Roundcube to the internet, the lasting risk is compromised credentials, not just a vulnerable web app. If a mail host accepts user logins from weak or stolen passwords, the session can become the foothold for full compromise even after the patch is applied.
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.