Description
Missing Host header validation and missing throttling of failed administrator sign-ins in the REST API listener of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote attacker to brute-force the server administrator's password through the administrator's own browser by DNS rebinding. The listener, which is off by default and bound to the loopback when enabled, answered requests whatever their Host header named, and a failed sign-in with the administrator's password from the loopback was neither auto-banned nor delayed. A web page whose host name the attacker rebinds to 127.0.0.1, opened in a browser on the server, can therefore send authenticated requests to the listener, read the answers and try administrator passwords at full speed until one is accepted, giving the attacker full administrative control of the mail server.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Administrative Account Compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing Host header validation and lack of throttling for failed administrator sign‑ins in the hMailServer REST API, allowing an attacker to perform a DNS‑rebinding attack and brute‑force the administrator password from within a victim’s own browser. Successful brute‑force yields full administrative control over the mail server, potentially exposing all hosted mailboxes and allowing further lateral movement.

Affected Systems

The affected product is Progressive Robot Ltd’s hMailServer, versions 6.0.0 through 6.3.5. These versions run the REST listener with no Host header filtering and no login attempt throttling.

Risk and Exploitability

With a CVSS score of 7.5 this issue presents a moderate to high severity. The EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, relying on DNS rebinding to trick a browser originating on the mail server into sending requests directly to the loopback‑bound REST listener. This allows the attacker to send authenticated requests at full speed, gaining administrative privileges if the password is guessed successfully. The lack of account lockout or delay mechanisms means that brute‑forcing can be performed rapidly until success.

Generated by OpenCVE AI on October 8, 2026 at 12:35 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, whose REST listener refuses an unexpected Host before any authentication and delays a wrong administrator password on every route. Until then: keep the REST API off (RestApiPort 0, the default) or reach it only through a reverse proxy that checks the Host header; give the administrator a long random password and enrol its second factor; do not browse the web from the server.


OpenCVE Recommended Actions

  • Upgrade hMailServer to version 6.3.6 or newer.
  • If upgrading is not immediately possible, disable the REST API by setting RestApiPort to 0 or restrict access via a reverse proxy that validates the Host header.
  • Use a strong, random administrator password and enable multi‑factor authentication for the admin account.
  • Avoid accessing the web interface from the mail server host to reduce potential DNS rebinding exploitation.

Generated by OpenCVE AI on October 8, 2026 at 12:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Missing Host header validation and missing throttling of failed administrator sign-ins in the REST API listener of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote attacker to brute-force the server administrator's password through the administrator's own browser by DNS rebinding. The listener, which is off by default and bound to the loopback when enabled, answered requests whatever their Host header named, and a failed sign-in with the administrator's password from the loopback was neither auto-banned nor delayed. A web page whose host name the attacker rebinds to 127.0.0.1, opened in a browser on the server, can therefore send authenticated requests to the listener, read the answers and try administrator passwords at full speed until one is accepted, giving the attacker full administrative control of the mail server.
Title Origin Validation Error in hMailServer
Weaknesses CWE-346
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T10:52:55.630Z

Reserved: 2026-10-02T07:38:59.115Z

Link: CVE-2026-104659

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:44.013

Modified: 2026-10-08T11:16:44.013

Link: CVE-2026-104659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T12:45:18Z

Weaknesses