Cross-Site Scripting in Progressive Robot hMailServer Webmail
CVE-2026-103647
8HIGH
What is CVE-2026-103647?
A cross-site scripting vulnerability exists in the webmail of Progressive Robot hMailServer versions 6.3.2 to 6.3.5. This allows a remote attacker, who can send an encrypted message, to execute scripts in the context of the webmail's origin using the affected user's session. Specifically, when a user opens decrypted S/MIME or OpenPGP message attachments in a browser, any content declared as text/html may be rendered, enabling attackers to exploit the REST API for unauthorized mailbox access, sending emails, and altering user accounts. Note that the webmail feature is only served with the REST API enabled, which is not the default configuration.
Affected Version(s)
hMailServer 6.3.2 < 6.3.6
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Found in the hMailServer project's own security review (Progressive Robot Ltd)
