Vulnerability record · CVE-2021-44026 · published 19 November 2021
CVE-2021-44026: Roundcube Webmail SQL injection via search parameters
Roundcube · Webmail
Roundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, making it a serious risk for exposed webmail instances.
Description
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCritical CVSS 9.8, unauthenticated network reachability, and CISA KEV listing with high EPSS probability make this an urgent patch target.
What it is
Roundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, making it a serious risk for exposed webmail instances.
Impact
An attacker can inject SQL through search parameters, potentially reading or modifying the underlying database, including mail and user data. Full compromise of confidentiality, integrity and availability is possible per the CVSS vector.
Attack surface
Reached over the network via the webmail search functionality; the CVSS vector shows no privileges or user interaction required. No further detail on the exact request path is given in the record.
Exploitation
CVE-2021-44026 is listed in CISA KEV with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.41856 (98.6th percentile). No ransomware campaign use is documented.
What to do
- Apply the Roundcube updates referenced in the vendor commits and distribution advisories (Debian DSA-5013, Fedora package announcements).
- Upgrade to Roundcube 1.3.17 or 1.4.12 or later as stated in the description.
- Restrict network access to Roundcube webmail where possible and place it behind authentication or a reverse proxy.
- Monitor vendor and distribution advisories for follow-up patches.
Detection
- Review web server and Roundcube logs for anomalous search or search_params requests containing SQL syntax.
- Enable and monitor database query logging for unexpected or malformed queries originating from the webmail application.
- Alert on exploitation attempts against known Roundcube SQL injection patterns in WAF or IDS telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-44026 to the Known Exploited Vulnerabilities catalog on 22 June 2023 as "Roundcube Webmail SQL Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 July 2023.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-44026 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-44026), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.