CVE-2026-107578: Improper Link Resolution Before File Access ('Link Following') in hMailServer
Improper link resolution and external control of file paths in the administrative command-line operations of hMailServer.exe in Progressive Robot hMailServer 6.3.4 and 6.3.5 allow a local attacker who already runs code as the low-privilege service account to escalate privilege. On Windows, operations run with administrator rights by the installer, DBSetup, the Control Panel or an administrator wrote log entries and crash records into the log folder, created, deleted and changed the permissions of the self-signed certificate and private key in the data folder, and rewrote message files in the data folder, all by path in folders the service account (NT SERVICE\hMailServer, the default for new installations since 6.3.4) can modify, following junctions and mount points; and the store-maintenance operations reached files by names taken from the database, which the service account can write, including names outside the data folder. On Linux, the store-maintenance and object-storage operations run as root followed symbolic links the service account (the packaged hmailserver user, which owns the data folder) planted in it, so a root-run operation read, wrote or removed the link's target as root. A local attacker controlling the service account can thereby gain the administrator's (Windows) or root's (Linux) privileges when such an operation is run.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progressive Robot hMailServerto a version that resolves this vulnerability.Fixed in 6.3.6 - Configuration
Until upgraded, run the Windows service as LocalSystem.
hMailServer Windows service service account = LocalSystem - Compensating control
Until upgraded, run Linux store-maintenance and object-storage commands only as the service user and never as root.
- Operational
Until upgraded, stop the Windows service and check the program folder's Logs, Data, Temp, and Database folders for junctions, mount points, and symbolic links; also verify that no message row names a path outside the data folder.
Event History
Frequently Asked Questions
Are default Windows installations exposed?
New Windows installations since 6.3.4 use the NT SERVICE\hMailServer service account by default. The affected paths are in folders that this account can modify, while certain administrative operations access them with administrator rights.
What does an attacker need before exploitation is possible?
The attacker must already be able to run code as the low-privilege hMailServer service account. They also need a privileged administrative or maintenance operation to process attacker-controlled paths or links.
Which operational actions create the privilege boundary?
On Windows, installer, DBSetup, Control Panel, or administrator-initiated operations can access logs, crash records, certificates, private keys, and message files with administrator rights. On Linux, root-run store-maintenance and object-storage operations can follow symbolic links planted by the packaged hmailserver service account.