๐Ÿ” CVE Alert

CVE-2026-104660

HIGH 7.8

Missing Authorization in hMailServer

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

Missing authorization on COM objects in Progressive Robot hMailServer 6.0.0 through 6.3.5 (Windows only) lets a local interactive user with no hMailServer credential read and write arbitrary files as the service account and queue mail as any sender. The service registers its COM classes with no DCOM access or launch permission and calls CoInitializeSecurity with no security descriptor, so any user logged on at the console or over Remote Desktop can activate the classes in the running service; a hMailServer.Message, its Attachments and Attachment, and a hMailServer.FetchAccount created this way carry a credential that never authenticated. Attachments.Add(path) and Attachment.SaveAs(path) performed no authorization check, and Message.Save/Copy and FetchAccount.AccountID/Save performed none either up to 6.3.3 and from 6.3.4 treated a holder with no credential as the server's own event-script host. Because the service does not impersonate the COM caller, Attachments.Add reads any file the service account can read and returns it, Attachment.SaveAs writes attacker-chosen bytes to any path it can write (on a LocalSystem installation, code execution as SYSTEM), Message.Save queues outbound mail from any address past the SMTP checks, and FetchAccount attaches a mail-fetch job to any mailbox. The objects an Application handed out behave the same once a later Authenticate on that Application fails.

CWE CWE-862
Vendor progressive robot ltd
Product hmailserver
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for progressive robot ltd hmailserver

Be the first to know when new high vulnerabilities affecting progressive robot ltd hmailserver are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Progressive Robot Ltd / hMailServer
6.0.0 < 6.3.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gitlab.com: https://gitlab.com/hmailserver/hmailserver/-/work_items/59 gitlab.com: https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6

Credits

Found in the hMailServer project's own security review (Progressive Robot Ltd)