Missing Authorization Vulnerability in Progressive Robot hMailServer
CVE-2026-104660

7.8HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-104660?

The Progressive Robot hMailServer is vulnerable due to missing authorization on COM objects, allowing local interactive users—without valid hMailServer credentials—to read and write arbitrary files as the service account. The affected versions exhibit a lack of proper DCOM access and launch permissions, enabling any logged-in user (locally or via Remote Desktop) to exploit this vulnerability. This oversight permits unauthorized actions, such as reading files accessible to the service account, writing to any location the service can access (potentially enabling code execution with SYSTEM privileges), and sending emails impersonating any sender due to insufficient authentication checks. The vulnerability exists in various hMailServer releases up to version 6.3.5.

Affected Version(s)

hMailServer 6.0.0 < 6.3.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.