Cross-Site Scripting in Progressive Robot hMailServer Webmail
CVE-2026-103647

8HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-103647?

A cross-site scripting vulnerability exists in the webmail of Progressive Robot hMailServer versions 6.3.2 to 6.3.5. This allows a remote attacker, who can send an encrypted message, to execute scripts in the context of the webmail's origin using the affected user's session. Specifically, when a user opens decrypted S/MIME or OpenPGP message attachments in a browser, any content declared as text/html may be rendered, enabling attackers to exploit the REST API for unauthorized mailbox access, sending emails, and altering user accounts. Note that the webmail feature is only served with the REST API enabled, which is not the default configuration.

Affected Version(s)

hMailServer 6.3.2 < 6.3.6

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.