Eval Injection Vulnerability in hMailServer by Progressive Robot Ltd
CVE-2026-100741
What is CVE-2026-100741?
An Eval injection vulnerability exists in the JScript event-script dispatcher of hMailServer by Progressive Robot Ltd. This flaw enables a remote, unauthenticated attacker to execute arbitrary JScript code within the hMailServer service process by crafting a login request containing a specific sequence—a backslash followed by an apostrophe—associated with a valid account. This exploitation requires specific configurations, including enabling event scripting and setting JScript as the script language, alongside defining certain event handlers such as OnClientValidatePassword. The attack vector also extends to events from POP3 and SMTP servers, making this a serious concern for users utilizing affected versions of the software.
Affected Version(s)
hMailServer 6.0.0 < 6.3.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
