Description
The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.
Published: 2026-10-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, whose helper takes the unit and the AppImage only from its own root-owned command line, refuses an AppImage request where that names none, confirms that the server has stopped, and verifies, runs and installs only copies it made after the stop, readable by root alone until they have verified. Install 6.3.6 with the package manager (apt or dnf) rather than through the live update. An AppImage run under the path unit keeps the helper script copied to /usr/lib/hmailserver/ when its update units were installed, which the AppImage's own update does not replace: copy 6.3.6's script there and give it --image in a drop-in for hmailserver-update.service. Until then: systemctl disable --now hmailserver-update.path, which turns the apply off while the update check and download go on. Windows, builds with -DHM_LIVE_UPDATE=OFF and the container image are not affected.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.
Title Reliance on Untrusted Inputs in a Security Decision in hMailServer
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T10:52:45.630Z

Reserved: 2026-10-02T07:38:54.248Z

Link: CVE-2026-104658

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:43.870

Modified: 2026-10-08T11:16:43.870

Link: CVE-2026-104658

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision