Appsecure logo

CVE-2021-44026: Critical Vulnerability in Roundcube Webmail

CVE-2021-44026 is a critical SQL injection vulnerability affecting Roundcube Webmail versions prior to 1.3.17 and 1.4.x prior to 1.4.12. Organizations must patch this vulnerability to prevent potential data breaches.

CRITICALKnown ExploitedCVSS 9.8 · Published November 19, 2021

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

CVE-2021-44026 is a critical SQL injection vulnerability affecting Roundcube Webmail, specifically versions prior to 1.3.17 and 1.4.x before 1.4.12. This vulnerability allows attackers to exploit the application through manipulated search parameters, leading to unauthorized database access. The vulnerability has been assigned a CVSS score of 9.8, categorizing it as critical due to its potential impact on confidentiality, integrity, and availability.

Risk to organizations includes significant data loss or corruption, as attackers can gain access to sensitive data stored in the database. Furthermore, the low complexity of the attack and the lack of required privileges make it an attractive target for malicious actors. Organizations utilizing affected versions of Roundcube Webmail must take immediate action to mitigate the risk.

The vulnerability was published on November 19, 2021, and is actively tracked in the Known Exploited Vulnerabilities (KEV) catalog, which indicates its relevance and potential for exploitation. Organizations should prioritize patching immediately to secure their systems.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.