Description
Missing authorization on COM objects in Progressive Robot hMailServer 6.0.0 through 6.3.5 (Windows only) lets a local interactive user with no hMailServer credential read and write arbitrary files as the service account and queue mail as any sender. The service registers its COM classes with no DCOM access or launch permission and calls CoInitializeSecurity with no security descriptor, so any user logged on at the console or over Remote Desktop can activate the classes in the running service; a hMailServer.Message, its Attachments and Attachment, and a hMailServer.FetchAccount created this way carry a credential that never authenticated. Attachments.Add(path) and Attachment.SaveAs(path) performed no authorization check, and Message.Save/Copy and FetchAccount.AccountID/Save performed none either up to 6.3.3 and from 6.3.4 treated a holder with no credential as the server's own event-script host. Because the service does not impersonate the COM caller, Attachments.Add reads any file the service account can read and returns it, Attachment.SaveAs writes attacker-chosen bytes to any path it can write (on a LocalSystem installation, code execution as SYSTEM), Message.Save queues outbound mail from any address past the SMTP checks, and FetchAccount attaches a mail-fetch job to any mailbox. The objects an Application handed out behave the same once a later Authenticate on that Application fails.
Published: 2026-10-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Local File Access and Mail Spoofing
Action: Immediate Patch
AI Analysis

Impact

Missing authorization on the COM objects of hMailServer 6.0.0 through 6.3.5 allows a local interactive user without hMailServer credentials to activate those objects and read or write any file that the service account can access. The exposed Attachments.Add, Attachment.SaveAs, and Message.Save methods perform no authentication checks, enabling the user to read arbitrary files, overwrite existing files, or create new ones on the server. Because the service runs under its service account and does not impersonate the caller, the attacker can write arbitrary data, potentially leading to code execution if that account has SYSTEM privileges, and can queue outbound mail from any address, bypassing SMTP checks.

Affected Systems

The vulnerability impacts Progressive Robot Ltd's hMailServer product version 6.0.0 through 6.3.5 on Windows operating systems. The affected components are the server's COM classes registered on the Windows machine, which are used by the hMailServer service and do not enforce DCOM access or launch permissions. Versions 6.3.6 and later include protection against this issue.

Risk and Exploitability

The CVSS v3.1 score of 7.8 indicates high severity, and the lack of an EPSS score shows limited public exploitation data at this time. The vulnerability is not listed in CISA's KEV catalog, access, such as console or Remote Desktop logon. An attacker simply opens a local PowerShell or VBScript session, activates a COM object, and can read or overwrite files, queue mails, or create fetch jobs, thereby compromising confidentiality, integrity, or the ability to send spam. If the service account is running as SYSTEM, the impact elevates to local privilege escalation and full code execution on the host.

Generated by OpenCVE AI on October 8, 2026 at 12:36 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, whose COM API refuses a message or fetch account that carries no credential outside the server's own event scripts, serves and writes a file on the server's disk through a message to the server administrator alone, and adds Application.CreateMessage() so a signed-in program composes mail that carries its credential. Until then: Do not allow untrusted users to log on interactively (console or Remote Desktop) to the server host. There is no configuration switch that closes this before 6.3.6; restricting the DCOM AppID's launch/access permission to exclude INTERACTIVE would also close it.


OpenCVE Recommended Actions

  • Upgrade hMailServer to version 6.3.6 or later.
  • If a patch cannot be applied immediately, deny interactive logon for non‑trusted users on the server host, including Remote Desktop access.
  • Optionally configure DCOM AppID launch permissions to exclude the INTERACTIVE launch permission to block access until the patch is applied.
  • Ensure the hMailServer service runs with minimal privileges and consider configuring the service account to avoid SYSTEM rights when possible.

Generated by OpenCVE AI on October 8, 2026 at 12:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Missing authorization on COM objects in Progressive Robot hMailServer 6.0.0 through 6.3.5 (Windows only) lets a local interactive user with no hMailServer credential read and write arbitrary files as the service account and queue mail as any sender. The service registers its COM classes with no DCOM access or launch permission and calls CoInitializeSecurity with no security descriptor, so any user logged on at the console or over Remote Desktop can activate the classes in the running service; a hMailServer.Message, its Attachments and Attachment, and a hMailServer.FetchAccount created this way carry a credential that never authenticated. Attachments.Add(path) and Attachment.SaveAs(path) performed no authorization check, and Message.Save/Copy and FetchAccount.AccountID/Save performed none either up to 6.3.3 and from 6.3.4 treated a holder with no credential as the server's own event-script host. Because the service does not impersonate the COM caller, Attachments.Add reads any file the service account can read and returns it, Attachment.SaveAs writes attacker-chosen bytes to any path it can write (on a LocalSystem installation, code execution as SYSTEM), Message.Save queues outbound mail from any address past the SMTP checks, and FetchAccount attaches a mail-fetch job to any mailbox. The objects an Application handed out behave the same once a later Authenticate on that Application fails.
Title Missing Authorization in hMailServer
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:25:20.499Z

Reserved: 2026-10-02T07:39:04.118Z

Link: CVE-2026-104660

cve-icon Vulnrichment

Updated: 2026-10-08T14:25:16.708Z

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:44.160

Modified: 2026-10-08T15:17:32.137

Link: CVE-2026-104660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T12:45:18Z

Weaknesses