CVE-2026-100741 is an eval-injection bug in Progressive Robot’s hMailServer: a self-hosted mail server that speaks SMTP, IMAP and POP3 and is used for company mailboxes, multi-domain hosting, and private on-premises mail. Under a particular Windows configuration, an unauthenticated network client can turn data supplied to the mail server into JScript executed by hMailServer.exe.
That is a remote foothold, not merely a mail-authentication problem. The injected code runs with the rights of the hMailServer service account. Before 6.2.25, it could create arbitrary COM objects; from 6.2.25 onward, it still can when the default ScriptAllowedObjects value of * is in place. That can include WScript.Shell, giving the script a route to operating-system command execution.
A backslash defeats the quote escape
The vulnerable path exists only when event scripting is enabled, JScript is selected, and an OnClientValidatePassword handler is defined. Event scripting is off by default and the default script language is VBScript, so this is not every hMailServer installation. But exposed mail protocols are exactly where an attacker can reach it: SMTP AUTH, POP3 or IMAP logon attempts naming an existing active account are sufficient; they do not need that account’s password.
The dispatcher inserted the submitted password into generated JScript source. It escaped apostrophes but not backslashes, so a password containing a backslash followed by an apostrophe could alter how the resulting string literal was parsed. The vendor’s patch replaces the narrow quote replacement with a JScript-literal escaping routine:
else if (sScriptLanguage == _T("JScript"))
{
- String sEscapedPassword = sPassword;
- sEscapedPassword.Replace(_T("'"), _T("\\'"));
+ String sEscapedPassword = ScriptServer::EscapeForJScriptLiteral(sPassword);
sEventCaller.Format(_T("OnClientValidatePassword(HMAILSERVER_ACCOUNT, '%s')"), sEscapedPassword.c_str());
}The important change is the handling of the attacker-controlled backslash before escapes are added. The same underlying mistake is reachable from a remote POP3 server’s message UID when OnExternalAccountDownload exists, and from an SMTP peer’s rejected-delivery error text when OnDeliveryFailed exists.
Windows JScript deployments need an immediate upgrade
Affected releases are Windows hMailServer 6.0.0 through 6.3.3; VBScript event scripts and Linux builds are not affected. The 6.3.4 release fixes the flaw. Administrators should install its Windows installer manually: the live updater will refuse this release because it has no Sigstore bundle. Until that is done, disable event scripting, or remove the three affected handlers and reload scripts.
There is no confirmed exploitation in the wild or confirmed related breach as of September 27, 2026. It was not in CISA’s KEV catalogue snapshot dated September 25, which predates publication, so teams should recheck that status. A vendor regression test technically reproduces the password path, but no standalone public exploit program or repository has surfaced.
For businesses and hosting providers running Windows hMailServer, configuration review matters as much as version inventory: identify JScript event handlers and externally reachable mail services, then patch. SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs.




