Sceawere

Vulnerability Detail

CVE-2026-104659UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer DNS Rebinding Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-346: Origin Validation Error
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Missing Host header validation and missing throttling of failed administrator sign-ins in the REST API listener of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote attacker to brute-force the server administrator's password through the administrator's own browser by DNS rebinding. The listener, which is off by default and bound to the loopback when enabled, answered requests whatever their Host header named, and a failed sign-in with the administrator's password from the loopback was neither auto-banned nor delayed. A web page whose host name the attacker rebinds to 127.0.0.1, opened in a browser on the server, can therefore send authenticated requests to the listener, read the answers and try administrator passwords at full speed until one is accepted, giving the attacker full administrative control of the mail server.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-08T11:16:44.013Z",
  "pubdate": "2026-10-08T11:16:44.013Z",
  "executiveSummary": "This vulnerability involves a combination of missing Host header validation and lack of rate-limiting within the REST API listener of Progressive Robot hMailServer versions 6.0.0 through 6.3.5. By leveraging DNS rebinding, a remote attacker can trick an administrator's browser into interacting with the local-only REST API listener.\nThe vulnerability allows an unauthenticated remote attacker to perform brute-force credential attacks against the server administrator account. Because the API fails to implement request throttling or delays for failed authentication attempts, an attacker can conduct high-speed password guessing. Successful exploitation grants the attacker full administrative control over the mail server, leading to potential data exfiltration, service manipulation, and compromise of all hosted email traffic.\nThe attack is facilitated by the service's failure to enforce strict origin checks, allowing requests originating from malicious external domains to communicate with the loopback-bound service. This poses a significant risk to the integrity and confidentiality of the mail server environment, requiring immediate remediation to prevent unauthorized administrative access.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper security configuration of the REST API listener in Progressive Robot hMailServer versions 6.0.0 through 6.3.5. The listener service exhibits two primary security deficiencies: the absence of Host header validation and the omission of account lockout or rate-limiting mechanisms for failed sign-in attempts.\nAlthough the REST API listener is disabled by default and restricted to the 127.0.0.1 (loopback) interface when enabled, it remains vulnerable to DNS rebinding attacks. In this scenario, an attacker induces the server administrator's web browser to navigate to a malicious domain controlled by the attacker. Through DNS rebinding, the attacker forces the browser to resolve the malicious domain to 127.0.0.1, effectively bypassing the same-origin policy restrictions that would otherwise prevent a web page from interacting with a service bound to the loopback interface.\nThe attack flow proceeds as follows: First, the attacker configures a DNS server to respond with a short Time-to-Live (TTL) record, initially pointing to an external malicious IP, then subsequently remapping the domain to 127.0.0.1. Once the administrator’s browser connects to the attacker’s malicious site, the browser executes JavaScript that initiates requests to the hMailServer REST API listener at the local loopback address. Because the API listener accepts requests regardless of the Host header provided, it processes the forged requests as if they were legitimate, locally sourced administrative commands.\nSince the REST API lacks security mechanisms such as account lockout, request throttling, or exponential back-off for failed authentication, the attacker can programmatically iterate through password dictionaries at maximum possible speed. The lack of validation for the Host header ensures that these requests are successfully routed to the target service. Upon correctly guessing the administrator's password, the attacker establishes an authenticated session.\nThe post-exploitation impact is critical, as it grants the attacker total administrative control over the hMailServer instance. This allows for the modification of mail server settings, creation of rogue accounts, interception of sensitive communications, and complete infrastructure compromise. The vulnerability is highly exploitable provided the administrator interacts with the malicious content while the REST API listener is active, rendering traditional network perimeter defenses ineffective against this browser-based attack vector."
}
CVE-2026-104659: hMailServer DNS Rebinding Authentication Bypass (HIGH Severity, CVSS: 7.5) | Sceawere