Missing Host Header Validation in Progressive Robot hMailServer
CVE-2026-104659

7.5HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-104659?

The Progressive Robot hMailServer exhibits a critical flaw due to missing host header validation and inadequate throttling mechanisms for failed administrator sign-ins in its REST API listener. This vulnerability allows attackers to exploit DNS rebinding techniques to send brute-force authentication requests to the server administrator's interface using their own browser. When the REST API listener is enabled, it responds to any host header, leading to unauthorized attempts at securing the administrator's password. The failure to auto-ban or delay login attempts means that attackers can rapidly attempt large volumes of credentials, compromising server security and potentially giving them full administrative rights over the mail server.

Affected Version(s)

hMailServer 6.0.0 < 6.3.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.