๐Ÿ” CVE Alert

CVE-2026-104658

HIGH 7.8

Reliance on Untrusted Inputs in a Security Decision in hMailServer

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.

CWE CWE-807
Vendor progressive robot ltd
Product hmailserver
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for progressive robot ltd hmailserver

Be the first to know when new high vulnerabilities affecting progressive robot ltd hmailserver are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Progressive Robot Ltd / hMailServer
6.3.4 < 6.3.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gitlab.com: https://gitlab.com/hmailserver/hmailserver/-/work_items/58 gitlab.com: https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6

Credits

Found in the hMailServer project's own security review (Progressive Robot Ltd)