CRITICAL
CVE-2021-44026
CVSS
9.8
KEV
Description
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
Summary dbcve.org
SQL injection vulnerability in Roundcube Webmail's search and search_params functionality, affecting versions before 1.3.17 and 1.4.x before 1.4.12. The flaw allows crafted input through search parameters to manipulate underlying database queries, potentially leading to data exfiltration or unauthorized access, with a CVSS 9.8 indicating remote, low-complexity exploitation likely without authentication.
Mitigation
Upgrade Roundcube to version 1.3.17 or 1.4.12 (or later) immediately. Verify all plugins and custom integrations are compatible with the patched release.
Weakness (CWE)
CWE-89
SQL Injection
EPSS Score
69.88%
Probability of exploitation in next 30 days
99.4th percentile
References
https://bugs.debian.org/1000156
Mailing List, Patch
https://github.com/roundcube/roundcubemail/commit/c8947ecb762d9e89c2091bda28d49002817263f1
Patch
https://github.com/roundcube/roundcubemail/commit/ee809bde2dcaa04857a919397808a7296681dcfa
Patch
https://lists.debian.org/debian-lts-announce/2021/12/msg00004.html
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NDVGIZMQJ5IOM47Y3SAAJRN5VPANKTKO/
Mailing List, Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TP3Y5RXTUUOUODNG7HFEKWYNIPIT2NL4/
Mailing List, Release Notes
https://www.debian.org/security/2021/dsa-5013
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44026
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.