Privilege Escalation Vulnerability in hMailServer by Progressive Robot
CVE-2026-107578
What is CVE-2026-107578?
A vulnerability exists in hMailServer versions 6.3.4 and 6.3.5 that allows a local attacker, who has compromised the low-privilege service account, to escalate their privileges. This occurs through improper link resolution and external control over file paths during administrative command-line operations. On Windows, log entries and crash records can be manipulated by operations running with administrator rights, affecting the log folder and the data folder. Meanwhile, on Linux, root-level operations can follow symbolic links planted by the service account, allowing unauthorized access to data and administrative privileges. This could lead to severe security implications if exploited.
Affected Version(s)
hMailServer 6.3.4 < 6.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
