CVE-2026-104658: Reliance on Untrusted Inputs in a Security Decision in hMailServer
The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progressive Robot hMailServerto a version that resolves this vulnerability.Fixed in 6.3.6 - Configuration
Run systemctl disable --now hmailserver-update.path to turn off the live-update apply step while update checking and downloading continue.
systemd hmailserver-update.path = disabled and stopped - Configuration
For AppImage installations run under the path unit, copy 6.3.6's helper script to /usr/lib/hmailserver/ and configure a drop-in for hmailserver-update.service that invokes it with --image.
hmailserver-update.service drop-in ExecStart = --image
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Linux installations with the live-update path unit active are affected. This is the default for the project's .deb and .rpm packages, and AppImage installations are affected when run under that unit.
What level of access does an attacker need to exploit it?
An attacker must already be able to run code as the unprivileged hmailserver service account. This could occur through a separate flaw in the mail server or another means of compromising that service account.
What is the impact after successful exploitation?
The attacker can cause arbitrary code to execute as root by controlling values in the update request file, including the signature-verification program and systemd unit to stop.
Which versions are identified as vulnerable?
Progressive Robot hMailServer 6.3.4 and 6.3.5 are identified as affected. The referenced release is v6.3.6.