CVE-2021-44026
Summary
| CVE | CVE-2021-44026 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-19 04:15:00 UTC |
| Updated | 2023-11-07 03:39:00 UTC |
| Description | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. |
Risk And Classification
EPSS: 0.725270000 probability, percentile 0.987750000 (date 2026-04-22)
CISA KEV: Listed on 2023-06-22; due 2023-07-13; ransomware use Unknown
Problem Types: CWE-89
CISA Known Exploited Vulnerability
| Vendor | Roundcube |
|---|---|
| Product | Roundcube Webmail |
| Name | Roundcube Webmail SQL Injection Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://roundcube.net/news/2021/11/12/security-updates-1.4.12-and-1.3.17-released; https://nvd.nist.gov/vuln/detail/CVE-2021-44026 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Application | Roundcube | Webmail | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Rename session items 'search' and 'search_params' to 'contact_search… · roundcube/roundcubemail@ee809bd · GitHub | MISC | github.com | |
| [SECURITY] Fedora 34 Update: roundcubemail-1.4.12-1.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| #1000156 - roundcube: XSS vulnerability in handling attachment filename extension in MIME type mismatch warnings - Debian Bug report logs | MISC | bugs.debian.org | |
| [SECURITY] Fedora 34 Update: roundcubemail-1.4.12-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Rename session items 'search' and 'search_params' to 'contact_search… · roundcube/roundcubemail@c8947ec · GitHub | MISC | github.com | |
| [SECURITY] [DLA 2840-1] roundcube security update | MLIST | lists.debian.org | |
| Debian -- Security Information -- DSA-5013-1 roundcube | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 33 Update: roundcubemail-1.4.12-1.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 33 Update: roundcubemail-1.4.12-1.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178911 Debian Security Update for roundcube (DSA 5013-1)
- 178930 Debian Security Update for roundcube (DLA 2840-1)
- 184364 Debian Security Update for roundcube (CVE-2021-44026)
- 282070 Fedora Security Update for roundcubemail (FEDORA-2021-167865df98)
- 282071 Fedora Security Update for roundcubemail (FEDORA-2021-43d3c10590)