CVE-2021-44026 is a critical SQL injection vulnerability affecting Roundcube versions before 1.3.17 and 1.4.x before 1.4.12, specifically impacting Debian, Fedora, and webmail installations. With a CVSS score of 9.8, this flaw allows unauthenticated remote attackers to execute arbitrary SQL commands, leading to full compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community discussion and media attention, including reports linking it to state-sponsored threat actors. Despite its active exploitation, no public exploit code is currently available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.17CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 1.4.0, < 1.4.12CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.