Protect Your Webmail: Upgrading RoundCube on Enhance Server

In the fast-evolving world of cybersecurity, vulnerabilities in widely-used software can have far-reaching consequences. RoundCube, a popular open-source webmail client, is no exception. When we published this article in November 2024, three vulnerabilities had recently been disclosed, and addressing them is crucial for securing your webmail environment. Here, we discuss those vulnerabilities, the importance of timely upgrades, and guide you through updating RoundCube on your Enhance Server.
Update: Enhance now documents automatic updates for central webmail and, from Enhance 12.20, per-server webmail. Start by checking your installed Enhance and Roundcube versions against the Enhance release notes. The manual steps below remain useful for an older or separately maintained installation; confirm that manual maintenance is appropriate before replacing managed files.
Recent Vulnerabilities in RoundCube
The following vulnerabilities in RoundCube prompted the original article, and updating to the latest version is strongly advised to mitigate these risks:
These security flaws are concerning as hackers often target RoundCube, especially given its usage among organizations handling sensitive data. Earlier in 2024, CISA issued a warning regarding CVE-2023-43770, a critical cross-site scripting (XSS) vulnerability, urging federal organizations to patch it within two weeks.
The original instructions used RoundCube 1.6.9; it is no longer a suitable update target. The examples below use 1.6.18, listed by Enhance on September 28, 2026. Before upgrading, check the supported version and read its upgrade notes on the official RoundCube release page.
Preparation for the Upgrade
Use administrator SSH access on the intended Enhance server running Ubuntu 22.04/24.04, and arrange a maintenance window. Back up the entire Roundcube installation and its database together, including configuration and custom plugins. Roundcube’s upgrade guide explains the backup and migration requirements; read the release’s UPGRADING and INSTALL files first.
Before upgrading, identify the user running the RoundCube container on your Enhance server. Typically, this is webmail_1. If you have modified this configuration, you can verify the user with:
cat /etc/passwd
Confirm the account’s home directory and that public_html contains the installation you intend to update. The sample usernames below come from the original layout; replace them if yours differ. Keep account and configuration details private. Check the release’s PHP requirements, rsync availability and the Roundcube database user’s schema-update permissions before proceeding.
Important: PHP Disabled Functions
In our recommended security setup, certain PHP functions are disabled. However, for the RoundCube upgrade, temporarily enable the system and escapeshellarg functions in the PHP configuration used by the upgrade command. Save your current disable_functions value first, and remove only the required names. If you use the original policy, the temporary list below is the example; do not overwrite a different policy blindly:
Navigate to Enhance Main Control Panel:
- Settings → Service settings → Application → php.ini
- For the original policy, the temporary
disable_functionsvalue was:
exec,passthru,shell_exec,escapeshellcmd,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname,pcntl_exec,expect_popen
Prefer a temporary override for the webmail website where available; a global change affects other websites too. Follow Enhance’s PHP settings guidance, and restore your saved value after the upgrade even if it fails.
Upgrading RoundCube
Run each command in order and stop on an error. The installer’s -y option accepts its prompts automatically, so confirm the target directory before running it. Do not clean up until the installer finishes successfully and webmail checks pass.
Step 1: Upgrade on Main Control Panel Server
# Log in as the RoundCube user:
su - webmail_1
# Download the reviewed RoundCube release:
wget https://github.com/roundcube/roundcubemail/releases/download/1.6.18/roundcubemail-1.6.18-complete.tar.gz
# Extract the files:
tar -xvzf roundcubemail-1.6.18-complete.tar.gz
cd roundcubemail-1.6.18
# Run the installer:
bin/installto.sh -y ../public_html
# After successful installation and webmail checks, clean up:
cd ~
rm -rf -- roundcubemail-1.6.18 roundcubemail-1.6.18-complete.tar.gz
Step 2: Upgrade on Secondary Servers in Your Cluster (Mail Servers Only)
For an older, manually maintained per-server installation, repeat the process on each affected secondary mail server using roundcubelocal as the user. Skip this manual step where Enhance manages the update:
su - roundcubelocal
wget https://github.com/roundcube/roundcubemail/releases/download/1.6.18/roundcubemail-1.6.18-complete.tar.gz
tar -xvzf roundcubemail-1.6.18-complete.tar.gz
cd roundcubemail-1.6.18
bin/installto.sh -y ../public_html
# After successful installation and webmail checks:
cd ~
rm -rf -- roundcubemail-1.6.18 roundcubemail-1.6.18-complete.tar.gz
Final Security Check
After the upgrade, verify the displayed Roundcube version, log in, send and receive a test message, and check address books, attachments and any custom plugins. Restore the saved PHP disabled-functions policy. If files or database migration failed, retain the error, stop repeating the installer, and restore the matching files and database backup together or ask Enhance support for help. Do not leave a publicly accessible installer enabled. Keeping RoundCube updated not only mitigates vulnerabilities but also strengthens your webmail’s overall security posture.
Conclusion
With cyber threats targeting known software vulnerabilities, staying proactive with updates is vital. By following these steps, you can keep your RoundCube instance on Enhance Server maintained and reduce exposure to known vulnerabilities.
Stay secure, stay updated!
Try cPFence Free for One Month
Bring server protection and monitoring together with cPFence v4+ for Enhance on Ubuntu 22.04/24.04.
Start free trial

