Privilege Escalation Vulnerability in Progressive Robot hMailServer
CVE-2026-104658

7.8HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-104658?

The hMailServer live-update apply helper, 'hmailserver-update', is designed to run as root, leading to potential privilege escalation when exploited by an attacker with access to the service account. The vulnerability arises from the service account's capability to control the update process, which allows arbitrary code execution at the root level. This risk is particularly pertinent on any Linux installations where the live update's path unit is active, which is the default for the .deb and .rpm packages. Attackers leveraging other flaws in the mail server can exploit this weakness to gain elevated privileges, posing serious security risks.

Affected Version(s)

hMailServer 6.3.4 < 6.3.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.