๐Ÿ” CVE Alert

CVE-2026-103010

HIGH 7.8

Heap-based Buffer Overflow in hMailServer

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.

CWE CWE-122
Vendor progressive robot ltd
Product hmailserver
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for progressive robot ltd hmailserver

Be the first to know when new high vulnerabilities affecting progressive robot ltd hmailserver are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Progressive Robot Ltd / hMailServer
6.0.0 < 6.3.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gitlab.com: https://gitlab.com/hmailserver/hmailserver/-/commit/135a1908ff820ed587d5f180f98c53bd010d8931 gitlab.com: https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.4 gitlab.com: https://gitlab.com/hmailserver/hmailserver/-/work_items/49

Credits

Found in the hMailServer project's own code review (Progressive Robot Ltd)