CVE-2017-16651

HIGH KEV

Roundcube Webmail <1.1.10, 1.2.x <1.2.7, 1.3.x <1.3.3 - Arbitrary File Access

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-16651 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 2 public exploits from researchers including ropbear, joel @ ndepthsecurity, stonepresto, thomascube, including a Metasploit module auxiliary/gather/roundcube_auth_file_read.

AI-analyzed exploit summary This Python script exploits CVE-2017-16651, a Local File Inclusion (LFI) vulnerability in Roundcube Webmail. It authenticates to the target, manipulates the timezone parameter to include arbitrary files, and retrieves the file content via a crafted request.

Description

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

Exploits (2)

nomisec WORKING POC 3 stars
by ropbear · local
https://github.com/ropbear/CVE-2017-16651

This Python script exploits CVE-2017-16651, a Local File Inclusion (LFI) vulnerability in Roundcube Webmail. It authenticates to the target, manipulates the timezone parameter to include arbitrary files, and retrieves the file content via a crafted request.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Roundcube Webmail (versions affected by CVE-2017-16651)
Auth required
Prerequisites: Valid credentials for Roundcube Webmail · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by joel @ ndepthsecurity, stonepresto, thomascube · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/roundcube_auth_file_read.rb

This Metasploit module exploits an authenticated file disclosure vulnerability in Roundcube Webmail (CVE-2017-16651) by manipulating the timezone parameter to read arbitrary files from the server's filesystem. It requires valid credentials and an active session.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Roundcube Webmail 1.1.0 to 1.3.2
Auth required
Prerequisites: Valid Roundcube credentials · Access to the login page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Issue Tracking, Release Notes, Third Party Advisory x_refsource_confirm
https://github.com/roundcube/roundcubemail/releases/tag/1.3.3
Issue Tracking, Vendor Advisory x_refsource_confirm
https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2017/11/msg00039.html
Issue Tracking, Release Notes, Third Party Advisory x_refsource_confirm
https://github.com/roundcube/roundcubemail/releases/tag/1.1.10
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101793
Issue Tracking, Release Notes, Third Party Advisory x_refsource_confirm
https://github.com/roundcube/roundcubemail/releases/tag/1.2.7
Issue Tracking, Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2017/dsa-4030
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/roundcube/roundcubemail/issues/6026
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclosure.html

Scores

CVSS v3 7.8
EPSS 0.4283
EPSS Percentile 98.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2017-11-08
InTheWild.io 2021-03-04
ENISA EUVD EUVD-2017-7838
CWE
CWE-552
Status published
Products (13)
debian/debian_linux 7.0
debian/debian_linux 9.0
roundcube/webmail 1.2.0
roundcube/webmail 1.2.1
roundcube/webmail 1.2.2
roundcube/webmail 1.2.3
roundcube/webmail 1.2.4
roundcube/webmail 1.2.5
roundcube/webmail 1.2.6
roundcube/webmail 1.3.0
... and 3 more
Published Nov 09, 2017
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026