Privilege Escalation Vulnerability in hMailServer by Progressive Robot
CVE-2026-107578

6.7MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107578?

A vulnerability exists in hMailServer versions 6.3.4 and 6.3.5 that allows a local attacker, who has compromised the low-privilege service account, to escalate their privileges. This occurs through improper link resolution and external control over file paths during administrative command-line operations. On Windows, log entries and crash records can be manipulated by operations running with administrator rights, affecting the log folder and the data folder. Meanwhile, on Linux, root-level operations can follow symbolic links planted by the service account, allowing unauthorized access to data and administrative privileges. This could lead to severe security implications if exploited.

Affected Version(s)

hMailServer 6.3.4 < 6.3.6

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.