CVE-2021-44026
roundcube webmail, fedoraproject fedora, debian linux
Published 19 Nov 2021 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 22 Jun 2023, with a remediation deadline of 13 Jul 2023 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
References
- bugs.debian.org/1000156 · Mailing List, Patch
- github.com/roundcube/roundcubemail/commit/c8947ecb762d9e89c2091bda28d49002817263f1 · Patch
- github.com/roundcube/roundcubemail/commit/ee809bde2dcaa04857a919397808a7296681dcfa · Patch
- lists.debian.org/debian-lts-announce/2021/12/msg00004.html · Mailing List, Third Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NDVGIZMQJ5IOM47Y3SAAJRN5VPANKTKO/ · Mailing List, Release Notes
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TP3Y5RXTUUOUODNG7HFEKWYNIPIT2NL4/ · Mailing List, Release Notes
- www.debian.org/security/2021/dsa-5013 · Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44026 · US Government Resource