CVE-2017-16651
KEV PoC massArbitrary File Disclosure in Roundcube Webmail via Attachment Plugins
CISA: Roundcube Webmail File Disclosure Vulnerability
Roundcube Webmail fails to adequately validate input handled alongside file-based attachment plugins, which are used by default, allowing an attacker to manipulate the file path held for an attachment and make the server read arbitrary files from the host. The flaw is triggered through crafted requests to Roundcube's attachment handling, where insufficient path validation permits traversal or absolute-path file reads. A successful attacker gains the ability to read files with the privileges of the web server user, which can expose sensitive data such as Roundcube's configuration (including database and IMAP credentials) and other files on the mail server. Any Roundcube deployment relying on the default file-based attachment handling is affected, a footprint that spans bundled hosting-provider webmail as well as standalone installations. CISA added CVE-2017-16651 to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, and EPSS ranks it in the 98th percentile with roughly a 37% chance of exploitation within 30 days.
What to do: Apply the vendor's patched Roundcube release per CISA's required action; this flaw was fixed in the 2017 security updates for each active branch (1.1.10, 1.2.7, and 1.3.4 or later). Until patched, disable or avoid file-based attachment plugins (such as the filesystem attachment driver) and review web server logs for suspicious attachment-path requests or unexpected file access. Because arbitrary file reads can disclose Roundcube configuration secrets, rotate database/IMAP credentials stored in the webmail configuration and check for follow-on compromise.
| Roundcube Webmail | affected range not specified in source data; per public advisories, releases prior to the vendor's 2017 security updates for each branch (fixed in 1.1.10, 1.2.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.
- Affected
- Roundcube Roundcube Webmail
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
In the news0 stories
No ingested article mentions this CVE yet.