Roundcube PoC exploit: exfiltrating emails with CVE-2021-44026

Опубликовано: 01 Июнь 2026
на канале: Pentest-Tools
2,615
24

As an internal research exercise, we took a look at CVE-2021-44026, an SQL injection vulnerability in the open-source mail client Roundcube.

Since no vulnerability is truly critical until there's proof of impact, we decided to write a PoC exploit which could extract authenticated users’ emails.

In this guide, you’ll find all the technical details you need to understand how this works, why we chose to develop this exploit, and how to use it in your ethical hacking engagements: https://pentest-tools.com/blog/roundc...
____________
💡 See ALL OUR TOOLS: https://pentest-tools.com/alltools
@ us on Twitter:   / pentesttoolscom  
Join 46k+ offensive security specialists on LinkedIn:   / pent.  .
Become a member of our community of cybersecurity enthusiasts and professionals:   / pentest_tool.  .

#PenetrationTesting #Pentesting #EthicalHacking #PentestToolsCom
____________
WHAT IS Pentest-Tools.com?

Use the Pentest-Tools.com platform to quickly detect and report vulnerabilities in websites and network infrastructures!

✔ 20+ tightly integrated penetration testing and ethical hacking tools for easier, faster, and more effective engagements
✔ Built for security professionals in charge of penetration testing and vulnerability assessments (VAPT)
✔ Painless vulnerability management: add manual findings, change risk levels, delete obsolete targets, create and export customizable reports (complete with vulnerability information and remediation suggestions)
✔ Instant overview of all open ports, services, and running software from all your targets in a central, unified view (Attack Surface)
✔ Comprehensive scanning options: scheduled scans, robust API, internal network scanning through VPN agent, scan multiple targets at the same time
✔ Flexible subscription: choose monthly billing and you can cancel anytime. Alternatively, choose the yearly plan and get a 15% discount!

"Pentest-Tools is great for streamlining any security engagement" - Tavis D., Security Engineering Manager

"The Pentest-Tools platform, by far, was the best that I found. Not only for the quality of the built-in tools, but also for the high quality of the technical team behind the platform. Being supported by a quality team is crucial for the professional involved in Pentesting to be successful." - Vagner N., DevOps Specialist

“Pentest-Tools.com is the Swiss Army Knife of scanning tools”
Mark D., Apple Certified Support Professional

See how our customers use the platform:
https://www.g2.com/products/pentest-t...