Security Flaw in Progressive Robot hMailServer Affecting Outbound SMTP Delivery
CVE-2026-104704

7.4HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-104704?

The hMailServer versions 6.0.0 through 6.3.5 exhibit a vulnerability in which TLS is not enforced for outbound SMTP deliveries when the mail exchanger's DNSSEC-validated TLSA records lack a DANE-EE record. This issue stems from the server's reliance solely on DANE-EE records, neglecting other valid TLSA records such as DANE-TA. Consequently, if an attacker gains an active position between the hMailServer and the recipient's mail exchanger, they can manipulate the STARTTLS negotiation, allowing email messages to be transmitted in cleartext, which might be susceptible to interception and alteration.

Affected Version(s)

hMailServer 6.0.0 < 6.3.6

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.