ZeroHour

CVE-2017-16651

KEV PoC mass

Arbitrary File Disclosure in Roundcube Webmail via Attachment Plugins

CISA: Roundcube Webmail File Disclosure Vulnerability

CVSS 3.1
7.8 high
EPSS
37%p98
Published
()
KEV added
AI analysis

Roundcube Webmail fails to adequately validate input handled alongside file-based attachment plugins, which are used by default, allowing an attacker to manipulate the file path held for an attachment and make the server read arbitrary files from the host. The flaw is triggered through crafted requests to Roundcube's attachment handling, where insufficient path validation permits traversal or absolute-path file reads. A successful attacker gains the ability to read files with the privileges of the web server user, which can expose sensitive data such as Roundcube's configuration (including database and IMAP credentials) and other files on the mail server. Any Roundcube deployment relying on the default file-based attachment handling is affected, a footprint that spans bundled hosting-provider webmail as well as standalone installations. CISA added CVE-2017-16651 to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, and EPSS ranks it in the 98th percentile with roughly a 37% chance of exploitation within 30 days.

What to do: Apply the vendor's patched Roundcube release per CISA's required action; this flaw was fixed in the 2017 security updates for each active branch (1.1.10, 1.2.7, and 1.3.4 or later). Until patched, disable or avoid file-based attachment plugins (such as the filesystem attachment driver) and review web server logs for suspicious attachment-path requests or unexpected file access. Because arbitrary file reads can disclose Roundcube configuration secrets, rotate database/IMAP credentials stored in the webmail configuration and check for follow-on compromise.

Affected
Roundcube Webmailaffected range not specified in source data; per public advisories, releases prior to the vendor's 2017 security updates for each branch (fixed in 1.1.10, 1.2.7
Estimated exposure
massmillions of end users via bundled hosting/education mail deployments plus tens of thousands of internet-exposed Roundcube instances — Roundcube ships as the default or bundled webmail client in cPanel and similar hosting stacks and is widely used by universities, ISPs and mail providers (millions of accounts), while public internet scans have shown tens of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

CISA Known Exploited Vulnerability
Affected
Roundcube Roundcube Webmail
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
roundcubedebian
Products
webmail, debian linux
Weakness
CWE-552
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.