CVE-2026-104658: Reliance on Untrusted Inputs in a Security Decision in hMailServer

Published Oct 8, 2026
·
Updated

The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.

Affected Software

1 affected component
Progressive Robot hMailServer=6.3.4, =6.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Progressive Robot hMailServer to a version that resolves this vulnerability.

    Fixed in 6.3.6
  2. Configuration

    Run systemctl disable --now hmailserver-update.path to turn off the live-update apply step while update checking and downloading continue.

    systemd hmailserver-update.path = disabled and stopped
  3. Configuration

    For AppImage installations run under the path unit, copy 6.3.6's helper script to /usr/lib/hmailserver/ and configure a drop-in for hmailserver-update.service that invokes it with --image.

    hmailserver-update.service drop-in ExecStart = --image

Event History

Oct 8, 2026
CVE Published
via MITRE·10:52 AM
Data Sourced
via MITRE·10:52 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Linux installations with the live-update path unit active are affected. This is the default for the project's .deb and .rpm packages, and AppImage installations are affected when run under that unit.

2

What level of access does an attacker need to exploit it?

An attacker must already be able to run code as the unprivileged hmailserver service account. This could occur through a separate flaw in the mail server or another means of compromising that service account.

3

What is the impact after successful exploitation?

The attacker can cause arbitrary code to execute as root by controlling values in the update request file, including the signature-verification program and systemd unit to stop.

4

Which versions are identified as vulnerable?

Progressive Robot hMailServer 6.3.4 and 6.3.5 are identified as affected. The referenced release is v6.3.6.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203