Missing Authorization Vulnerability in Progressive Robot hMailServer
CVE-2026-104660
What is CVE-2026-104660?
The Progressive Robot hMailServer is vulnerable due to missing authorization on COM objects, allowing local interactive users—without valid hMailServer credentials—to read and write arbitrary files as the service account. The affected versions exhibit a lack of proper DCOM access and launch permissions, enabling any logged-in user (locally or via Remote Desktop) to exploit this vulnerability. This oversight permits unauthorized actions, such as reading files accessible to the service account, writing to any location the service can access (potentially enabling code execution with SYSTEM privileges), and sending emails impersonating any sender due to insufficient authentication checks. The vulnerability exists in various hMailServer releases up to version 6.3.5.
Affected Version(s)
hMailServer 6.0.0 < 6.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
