CVE-2021-28811: Roonlabs Roon Server

High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has already fixed this vulnerability in the following versions: Roon Server 2021-05-18 and later

Affected products

  • Roonlabs Roon Server: before 2021-05-18 (fixed in 2021-05-18)

Published 2021-06-08. Last modified 2026-06-17.