Missing Host Header Validation in Progressive Robot hMailServer
CVE-2026-104659
What is CVE-2026-104659?
The Progressive Robot hMailServer exhibits a critical flaw due to missing host header validation and inadequate throttling mechanisms for failed administrator sign-ins in its REST API listener. This vulnerability allows attackers to exploit DNS rebinding techniques to send brute-force authentication requests to the server administrator's interface using their own browser. When the REST API listener is enabled, it responds to any host header, leading to unauthorized attempts at securing the administrator's password. The failure to auto-ban or delay login attempts means that attackers can rapidly attempt large volumes of credentials, compromising server security and potentially giving them full administrative rights over the mail server.
Affected Version(s)
hMailServer 6.0.0 < 6.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
