Description
Improper link resolution and external control of file paths in the administrative command-line operations of hMailServer.exe in Progressive Robot hMailServer 6.3.4 and 6.3.5 allow a local attacker who already runs code as the low-privilege service account to escalate privilege. On Windows, operations run with administrator rights by the installer, DBSetup, the Control Panel or an administrator wrote log entries and crash records into the log folder, created, deleted and changed the permissions of the self-signed certificate and private key in the data folder, and rewrote message files in the data folder, all by path in folders the service account (NT SERVICE\hMailServer, the default for new installations since 6.3.4) can modify, following junctions and mount points; and the store-maintenance operations reached files by names taken from the database, which the service account can write, including names outside the data folder. On Linux, the store-maintenance and object-storage operations run as root followed symbolic links the service account (the packaged hmailserver user, which owns the data folder) planted in it, so a root-run operation read, wrote or removed the link's target as root. A local attacker controlling the service account can thereby gain the administrator's (Windows) or root's (Linux) privileges when such an operation is run.
Published: 2026-10-08
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper link resolution flaw in administrative command-line operations of hMailServer, allowing a local attacker with service account privileges to write paths that follow junctions, mount points, or symbolic links to files outside the legitimate data directory. This flaw enables the attacker to overwrite logs, change certificates, or modify message files, thereby bypassing security boundaries. The flaw is a classic example of improper control of path names (CWE‑59).

Affected Systems

The vulnerability affects Progressive Robot Ltd’s hMailServer versions 6.3.4 and 6.3.5 on both Windows and Linux platforms. On Windows, the flaw is exploitable through installer, DBSetup, Control Panel, or administrative operations that run with elevated rights. On Linux, the flaw is exploitable during store‑maintenance or object‑storage operations that run as root and follow symbolic links planted by the service user. Version 6.3.6 eliminates the flaw by tightening path resolution and restricting file access to the data folder.

Risk and Exploitability

The CVSS score of 6.7 indicates a medium level severity, and the EPSS score is not available, but the absence from the KEV catalog suggests no known public exploitation. Attackers can elevate from the service account to administrator or root by executing privileged operations that follow malicious links. The vulnerability requires local code execution with service account rights, and the attacker must trigger one of the administrative commands that resolve external paths. Because the flaw is local, the risk to remote users is limited; however, compromised service accounts can lead to full control over the server.

Generated by OpenCVE AI on October 8, 2026 at 13:22 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, in which every administrative command writes nothing to the logs and arms no crash recorder, writes the certificate only through folders held open and checked from the drive's root, reaches no file a database row names outside the data folder, and walks the data folder before any store command - going through a junction or mount point only when the administrators alone own and control it and refusing any other; and on Linux a store or object-storage command run as root first drops to the service account, so it follows no link that account planted. Until then: on Windows run the service as LocalSystem, or stop the service and check the program folder's Logs, Data, Temp and Database folders for junctions, mount points and symbolic links and that no message row names a path outside the data folder; on Linux run the store commands only as the service user, never as root.


OpenCVE Recommended Actions

  • Upgrade hMailServer to version 6.3.6, which eliminates the path resolution flaw and adds stricter ownership checks.
  • On Windows, configure the hMailServer service to run as LocalSystem, then stop the service, scan the Logs, Data, Temp, and Database folders for junctions, mount points, or symbolic links, and verify that no message rows reference paths outside the data folder.
  • On Linux, run store and object‑storage commands exclusively as the hmailserver service user; avoid executing these commands as root to prevent link traversal.
  • If an immediate upgrade is not possible, restrict write permissions on the data directory to the service account and block any symbolic link creation by the service account to reduce the attack surface.

Generated by OpenCVE AI on October 8, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
Description Improper link resolution and external control of file paths in the administrative command-line operations of hMailServer.exe in Progressive Robot hMailServer 6.3.4 and 6.3.5 allow a local attacker who already runs code as the low-privilege service account to escalate privilege. On Windows, operations run with administrator rights by the installer, DBSetup, the Control Panel or an administrator wrote log entries and crash records into the log folder, created, deleted and changed the permissions of the self-signed certificate and private key in the data folder, and rewrote message files in the data folder, all by path in folders the service account (NT SERVICE\hMailServer, the default for new installations since 6.3.4) can modify, following junctions and mount points; and the store-maintenance operations reached files by names taken from the database, which the service account can write, including names outside the data folder. On Linux, the store-maintenance and object-storage operations run as root followed symbolic links the service account (the packaged hmailserver user, which owns the data folder) planted in it, so a root-run operation read, wrote or removed the link's target as root. A local attacker controlling the service account can thereby gain the administrator's (Windows) or root's (Linux) privileges when such an operation is run.
Title Improper Link Resolution Before File Access ('Link Following') in hMailServer
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:17:57.729Z

Reserved: 2026-10-08T10:51:55.636Z

Link: CVE-2026-107578

cve-icon Vulnrichment

Updated: 2026-10-08T14:17:54.521Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T12:17:15.787

Modified: 2026-10-08T21:02:43.860

Link: CVE-2026-107578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T13:30:18Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')