CVE-2026-104660: Missing Authorization in hMailServer

Published Oct 8, 2026
·
Updated

Missing authorization on COM objects in Progressive Robot hMailServer 6.0.0 through 6.3.5 (Windows only) lets a local interactive user with no hMailServer credential read and write arbitrary files as the service account and queue mail as any sender. The service registers its COM classes with no DCOM access or launch permission and calls CoInitializeSecurity with no security descriptor, so any user logged on at the console or over Remote Desktop can activate the classes in the running service; a hMailServer.Message, its Attachments and Attachment, and a hMailServer.FetchAccount created this way carry a credential that never authenticated. Attachments.Add(path) and Attachment.SaveAs(path) performed no authorization check, and Message.Save/Copy and FetchAccount.AccountID/Save performed none either up to 6.3.3 and from 6.3.4 treated a holder with no credential as the server's own event-script host. Because the service does not impersonate the COM caller, Attachments.Add reads any file the service account can read and returns it, Attachment.SaveAs writes attacker-chosen bytes to any path it can write (on a LocalSystem installation, code execution as SYSTEM), Message.Save queues outbound mail from any address past the SMTP checks, and FetchAccount attaches a mail-fetch job to any mailbox. The objects an Application handed out behave the same once a later Authenticate on that Application fails.

Affected Software

1 affected component
Progressive Robot hMailServer>=6.0.0<=6.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade hMailServer to a version that resolves this vulnerability.

    Fixed in 6.3.6
  2. Configuration

    Restrict the DCOM AppID launch and access permissions to exclude INTERACTIVE users.

    hMailServer DCOM AppID launch/access permission = Exclude INTERACTIVE
  3. Compensating control

    Do not allow untrusted users to log on interactively, including through the console or Remote Desktop, to the hMailServer host.

Event History

Oct 8, 2026
CVE Published
via MITRE·10:52 AM
Data Sourced
via MITRE·10:52 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are realistically exposed?

Only Windows installations of hMailServer 6.0.0 through 6.3.5 are affected. Exploitation requires a user who can log on interactively at the console or through Remote Desktop.

2

Does an attacker need hMailServer credentials?

No. A local interactive user can activate the service COM classes without hMailServer credentials because the COM configuration does not require DCOM access or launch permission.

3

What privileges could exploitation provide?

The attacker can read files readable by the hMailServer service account, write attacker-controlled data to locations writable by that account, and queue mail using arbitrary senders. If the service runs as LocalSystem, the arbitrary file-write capability can lead to code execution as SYSTEM.

4

Are installations running 6.3.4 or 6.3.5 protected by the credential changes?

No. The issue affects versions through 6.3.5; from 6.3.4, an unauthenticated holder is treated as the server's event-script host rather than being denied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203