CVE-2026-107578: Improper Link Resolution Before File Access ('Link Following') in hMailServer

Published Oct 8, 2026
·
Updated

Improper link resolution and external control of file paths in the administrative command-line operations of hMailServer.exe in Progressive Robot hMailServer 6.3.4 and 6.3.5 allow a local attacker who already runs code as the low-privilege service account to escalate privilege. On Windows, operations run with administrator rights by the installer, DBSetup, the Control Panel or an administrator wrote log entries and crash records into the log folder, created, deleted and changed the permissions of the self-signed certificate and private key in the data folder, and rewrote message files in the data folder, all by path in folders the service account (NT SERVICE\hMailServer, the default for new installations since 6.3.4) can modify, following junctions and mount points; and the store-maintenance operations reached files by names taken from the database, which the service account can write, including names outside the data folder. On Linux, the store-maintenance and object-storage operations run as root followed symbolic links the service account (the packaged hmailserver user, which owns the data folder) planted in it, so a root-run operation read, wrote or removed the link's target as root. A local attacker controlling the service account can thereby gain the administrator's (Windows) or root's (Linux) privileges when such an operation is run.

Affected Software

1 affected component
Progressive Robot hMailServer=6.3.4, =6.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Progressive Robot hMailServer to a version that resolves this vulnerability.

    Fixed in 6.3.6
  2. Configuration

    Until upgraded, run the Windows service as LocalSystem.

    hMailServer Windows service service account = LocalSystem
  3. Compensating control

    Until upgraded, run Linux store-maintenance and object-storage commands only as the service user and never as root.

  4. Operational

    Until upgraded, stop the Windows service and check the program folder's Logs, Data, Temp, and Database folders for junctions, mount points, and symbolic links; also verify that no message row names a path outside the data folder.

Event History

Oct 8, 2026
CVE Published
via MITRE·11:47 AM
Data Sourced
via MITRE·11:47 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Are default Windows installations exposed?

New Windows installations since 6.3.4 use the NT SERVICE\hMailServer service account by default. The affected paths are in folders that this account can modify, while certain administrative operations access them with administrator rights.

2

What does an attacker need before exploitation is possible?

The attacker must already be able to run code as the low-privilege hMailServer service account. They also need a privileged administrative or maintenance operation to process attacker-controlled paths or links.

3

Which operational actions create the privilege boundary?

On Windows, installer, DBSetup, Control Panel, or administrator-initiated operations can access logs, crash records, certificates, private keys, and message files with administrator rights. On Linux, root-run store-maintenance and object-storage operations can follow symbolic links planted by the packaged hmailserver service account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203