Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to hMailServer 6.3.6, whose COM API refuses a message or fetch account that carries no credential outside the server's own event scripts, serves and writes a file on the server's disk through a message to the server administrator alone, and adds Application.CreateMessage() so a signed-in program composes mail that carries its credential. Until then: Do not allow untrusted users to log on interactively (console or Remote Desktop) to the server host. There is no configuration switch that closes this before 6.3.6; restricting the DCOM AppID's launch/access permission to exclude INTERACTIVE would also close it.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progressive Robot
Progressive Robot hmailserver |
|
| Vendors & Products |
Progressive Robot
Progressive Robot hmailserver |
Thu, 08 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization on COM objects in Progressive Robot hMailServer 6.0.0 through 6.3.5 (Windows only) lets a local interactive user with no hMailServer credential read and write arbitrary files as the service account and queue mail as any sender. The service registers its COM classes with no DCOM access or launch permission and calls CoInitializeSecurity with no security descriptor, so any user logged on at the console or over Remote Desktop can activate the classes in the running service; a hMailServer.Message, its Attachments and Attachment, and a hMailServer.FetchAccount created this way carry a credential that never authenticated. Attachments.Add(path) and Attachment.SaveAs(path) performed no authorization check, and Message.Save/Copy and FetchAccount.AccountID/Save performed none either up to 6.3.3 and from 6.3.4 treated a holder with no credential as the server's own event-script host. Because the service does not impersonate the COM caller, Attachments.Add reads any file the service account can read and returns it, Attachment.SaveAs writes attacker-chosen bytes to any path it can write (on a LocalSystem installation, code execution as SYSTEM), Message.Save queues outbound mail from any address past the SMTP checks, and FetchAccount attaches a mail-fetch job to any mailbox. The objects an Application handed out behave the same once a later Authenticate on that Application fails. | |
| Title | Missing Authorization in hMailServer | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T10:52:50.630Z
Reserved: 2026-10-02T07:39:04.118Z
Link: CVE-2026-104660
No data.
Status : Received
Published: 2026-10-08T11:16:44.160
Modified: 2026-10-08T11:16:44.160
Link: CVE-2026-104660
No data.
OpenCVE Enrichment
Updated: 2026-10-08T12:45:18Z
-
CWE-862
Missing Authorization