Sceawere
Vulnerability Detail
CVE-2026-100741UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
hMailServer JScript Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 1d ago
- Vendor
- Progressive Robot Ltd
- Product
- hMailServer
- Attack Type
- CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password containing a backslash followed by an apostrophe, sent in any logon (SMTP AUTH, POP3, IMAP) that names an existing, active account. Exploitation requires a non-default configuration: event scripting enabled (off by default), the script language set to JScript (the default is VBScript), and an OnClientValidatePassword handler defined in the event script. The server wrote event values into the handler call as JScript string literals, escaping the apostrophe but not the backslash, so such a value closes the literal and the rest of it is parsed as script. The same flaw is reachable by a remote POP3 server through the message UID it returns, where an OnExternalAccountDownload handler is defined, and by a remote SMTP server through the error reply it rejects a delivery with, where an OnDeliveryFailed handler is defined. Before 6.2.25 the injected script can create any COM object, and from 6.2.25 it can with the default ScriptAllowedObjects value of '*'; WScript.Shell among them gives command execution as the service account. VBScript event scripts and the Linux builds of Progressive Robot Ltd's hMailServer are not affected.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-09-27T08:16:26.813Z",
"pubdate": "2026-09-27T08:16:26.813Z",
"executiveSummary": "This vulnerability is an Eval injection flaw residing within the JScript event-script dispatcher of Progressive Robot Ltd's hMailServer, affecting versions 6.0.0 through 6.3.3 on Windows platforms.\nThe issue allows a remote, unauthenticated attacker to execute arbitrary JScript code within the context of the hMailServer service process.\nExploitation grants the attacker the full privileges of the service account, which often entails system-level or high-privileged execution.\nThe vulnerability is triggered by providing a malicious password string containing a backslash and an apostrophe sequence during various logon protocols, including SMTP AUTH, POP3, and IMAP, provided the target account exists.\nSuccessful exploitation requires specific non-default configurations: the event scripting feature must be enabled, the scripting language must be configured to JScript, and specific event handlers (OnClientValidatePassword, OnExternalAccountDownload, or OnDeliveryFailed) must be defined.\nDue to the ability to instantiate COM objects, such as WScript.Shell, this flaw presents a severe security risk, potentially leading to full system compromise.\nVBScript event handlers and Linux deployments are not susceptible to this specific injection vector.",
"technicalDetails": "The root cause of this vulnerability is an improper input sanitization failure within the JScript event-script dispatcher. The application constructs JScript string literals dynamically by inserting user-supplied event values into handler calls. While the implementation attempts to escape the apostrophe character, it fails to properly escape the backslash character.\nAn attacker can exploit this by crafting a specific input string consisting of a backslash followed by an apostrophe (\\'). When processed, the backslash escapes the escape character itself, effectively leaving the apostrophe unescaped. This allows the input to prematurely terminate the intended JScript string literal and inject arbitrary script code that is subsequently evaluated by the JScript engine.\nThe attack flow varies based on the exposed event handler. In the context of logon protocols (SMTP AUTH, POP3, IMAP), the attacker provides the malicious payload as a password. If an OnClientValidatePassword handler is defined, the server passes this payload to the script. Similarly, if an OnExternalAccountDownload handler is active, the vulnerability can be reached via a remote POP3 server returning a malicious message UID. If an OnDeliveryFailed handler is present, an attacker can trigger the injection through a remote SMTP server's error reply during a failed delivery attempt.\nOnce the injection occurs, the arbitrary script executes under the security context of the hMailServer service process. Prior to version 6.2.25, or in environments where the ScriptAllowedObjects registry value is set to '*', the injected code can instantiate arbitrary COM objects. Utilizing the WScript.Shell COM object, an attacker can execute arbitrary system commands, leading to full remote code execution, persistence, or data exfiltration.\nThe requirement for non-default configurations—specifically enabling event scripting and setting the language to JScript—serves as a primary barrier to exploitation. However, in environments where these features are enabled for legitimate automation, the attack surface is significant, as it does not require prior authentication to the mail service."
}