{"id":"CVE-2021-44026","aliases":["BIT-roundcube-2021-44026"],"url":"https://o3.security/vulnerability/CVE-2021-44026","summary":null,"details":"Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.","published":"2021-11-19T04:15:07.197Z","modified":"2026-08-07T11:49:16.232261547Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.41856,"percentile":0.98595,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[],"fix":{"url":"https://github.com/roundcube/roundcubemail/commit/c8947ecb762d9e89c2091bda28d49002817263f1","label":"roundcube/roundcubemail@c8947ec"},"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44026"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00004.html"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NDVGIZMQJ5IOM47Y3SAAJRN5VPANKTKO/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TP3Y5RXTUUOUODNG7HFEKWYNIPIT2NL4/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-5013"},{"type":"FIX","url":"https://bugs.debian.org/1000156"},{"type":"FIX","url":"https://github.com/roundcube/roundcubemail/commit/c8947ecb762d9e89c2091bda28d49002817263f1"},{"type":"FIX","url":"https://github.com/roundcube/roundcubemail/commit/ee809bde2dcaa04857a919397808a7296681dcfa"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:49:16.232261547Z"}}