Description
The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.
Published: 2026-10-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

The Linux live‑update apply helper (hmailserver‑update) runs as root based on a request file written by the unprivileged hmailserver service account, and uses that file to determine which program to run for signature verification and which systemd unit to stop before reading the service account's files. An attacker who can execute code as the hmailserver account, for example through another flaw in the mail server, can therefore obtain arbitrary root privileges by crafting a malicious request, causing the helper to execute attacker‑supplied code as root. This privilege escalation can be applied to any Linux installation where the live‑update path unit is active – the default for the project's .deb and .rpm packages – and to AppImage installations that run under that unit.

Affected Systems

The vulnerability affects Progressive Robot's hMailServer versions 6.3.4 and 6.3.5 running on Linux. The flaw is mitigated in hMailServer 6.3.6, where the helper limits input to its own root‑owned command line, refuses unnamed AppImage requests, and ensures the server is stopped before processing, verifying, and installing only locally‑created, root‑readable copies. Users of the default package managers (apt or dnf) or of AppImage installations that rely on the live‑update path unit are therefore at risk if they remain on the affected versions.

Risk and Exploitability

The CVSS score of 7.8 denotes a high severity vulnerability, and while the EPSS score is not available, the lack of a KEV listing suggests limited public exploitation so far. However, the attack requires local code execution as the hmailserver service account, which can be achieved via other, potentially already exploited, flaws. Once such foothold is gained, the untrusted request file allows the helper to run arbitrary payloads as root, giving full system control. The risk is therefore high for affected deployments that have not applied the latest patch or disabled the live‑update path unit.

Generated by OpenCVE AI on October 8, 2026 at 12:36 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, whose helper takes the unit and the AppImage only from its own root-owned command line, refuses an AppImage request where that names none, confirms that the server has stopped, and verifies, runs and installs only copies it made after the stop, readable by root alone until they have verified. Install 6.3.6 with the package manager (apt or dnf) rather than through the live update. An AppImage run under the path unit keeps the helper script copied to /usr/lib/hmailserver/ when its update units were installed, which the AppImage's own update does not replace: copy 6.3.6's script there and give it --image in a drop-in for hmailserver-update.service. Until then: systemctl disable --now hmailserver-update.path, which turns the apply off while the update check and download go on. Windows, builds with -DHM_LIVE_UPDATE=OFF and the container image are not affected.


OpenCVE Recommended Actions

  • Upgrade to hMailServer 6.3.6 or later using the package manager (apt or dnf) instead of the live update mechanism.
  • Immediately disable the live‑update path unit with `systemctl disable --now hmailserver-update.path` while applying the fix to prevent further exploitation.
  • If using AppImage installations, copy the 6.3.6 helper script to `/usr/lib/hmailserver/` and configure it with `--image` in the drop‑in for `hmailserver-update.service` to ensure the safer behavior.
  • Remediate any other vulnerabilities that allow execution under the hmailserver service account, and monitor the environment for signs of exploitation.

Generated by OpenCVE AI on October 8, 2026 at 12:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.
Title Reliance on Untrusted Inputs in a Security Decision in hMailServer
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T10:52:45.630Z

Reserved: 2026-10-02T07:38:54.248Z

Link: CVE-2026-104658

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:43.870

Modified: 2026-10-08T11:16:43.870

Link: CVE-2026-104658

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T12:45:18Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision