Improper Certificate Validation in hMailServer by Progressive Robot
CVE-2026-107587

5.9MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107587?

An improper certificate validation issue in the webmail functionality of hMailServer versions 6.3.2 to 6.3.5 permits remote attackers to exploit S/MIME encryption. When an email signed with a certificate is sent to a recipient, the webmail stores the signer's certificate for future replies, regardless of the trust status of the certificate chain. This results in subsequent emails being encrypted with potentially malicious certificates, enabling unauthorized decryption by attackers who access the private key associated with the stored certificate.

Affected Version(s)

hMailServer 6.3.2 < 6.3.6

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.