CVE-2026-104658
Reliance on Untrusted Inputs in a Security Decision in hMailServer
The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.
| CWE | CWE-807 |
| Vendor | progressive robot ltd |
| Product | hmailserver |
| Published | Oct 8, 2026 |
Get instant alerts for progressive robot ltd hmailserver
Be the first to know when new high vulnerabilities affecting progressive robot ltd hmailserver are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H