Sceawere

Vulnerability Detail

CVE-2026-104704UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer DANE TLS Enforcement Failure

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
3h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-319: Cleartext Transmission of Sensitive Information
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Progressive Robot hMailServer 6.0.0 through 6.3.5 does not enforce TLS for outbound SMTP delivery to a mail exchanger whose DNSSEC-validated TLSA records contain no DANE-EE (usage 3) record, contrary to RFC 7672 section 2.2. The server used only DANE-EE records and treated a validated TLSA record set consisting of DANE-TA (usage 2) or otherwise unusable records as if no records were published, so delivery to such a host fell back to opportunistic TLS. An attacker with an active position on the network path between the server and the recipient's mail exchanger can suppress or break the STARTTLS negotiation and cause messages to be delivered in cleartext, where they can be read and modified.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-10-08T11:16:44.457Z",
  "pubdate": "2026-10-08T11:16:44.457Z",
  "executiveSummary": "hMailServer versions 6.0.0 through 6.3.5 suffer from a critical DANE (DNS-based Authentication of Named Entities) implementation flaw during outbound SMTP delivery.\nThe vulnerability occurs because the mail server fails to strictly enforce TLS when a DNSSEC-validated TLSA record set does not include a DANE-EE (usage 3) record, violating RFC 7672 requirements.\nBy incorrectly interpreting DANE-TA (usage 2) records or other valid but non-EE TLSA records as an absence of security policy, the server defaults to opportunistic TLS.\nThis behavior exposes the communication to Man-in-the-Middle (MitM) attacks, where an adversary can strip STARTTLS commands, forcing the connection to cleartext.\nSuccessful exploitation allows attackers to intercept, read, or modify sensitive email traffic in transit without detection.\nThe vulnerability is inherent to the outbound SMTP delivery logic, affecting any deployment of hMailServer within the specified version range.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper state machine logic within hMailServer's SMTP client regarding DANE TLSA record validation. According to RFC 7672 section 2.2, a sender must adhere to the security policies defined by validated TLSA records.\nhMailServer exhibits a restrictive and incorrect validation process that exclusively prioritizes DANE-EE (usage 3) records. When the server performs a DNS query for TLSA records and receives a validated set containing DANE-TA (usage 2) or other valid TLSA parameters—but lacking a DANE-EE record—the software erroneously concludes that no DANE policy is applicable.\nThis failure to recognize valid TLSA records triggers an unintended fallback to opportunistic TLS. Unlike mandatory DANE, opportunistic TLS does not provide cryptographic assurance that the remote MX server's identity has been verified against the published TLSA records.\nAn attacker positioned on the network path (e.g., through ARP poisoning, BGP hijacking, or compromised transit infrastructure) can exploit this by conducting an active intercept on the STARTTLS negotiation. When the hMailServer attempts to establish a secure connection, the attacker can block or inject responses to the STARTTLS command, effectively downgrading the connection to plaintext.\nBecause the server has downgraded its security posture from mandatory DANE to opportunistic TLS, it proceeds to transmit the email without requiring a valid certificate chain or matching the TLSA record. Consequently, the cleartext traffic is fully accessible to the attacker, who can monitor, exfiltrate, or alter the message content before relaying it to the destination mail exchanger.\nThis vulnerability is present in versions 6.0.0 through 6.3.5. Exploitation requires no authentication or specialized privileges, only the ability to intercept network traffic between the hMailServer and the target mail exchanger. No specific payload is required; the vulnerability is triggered by the natural interaction between the server's broken validation logic and standard network conditions where the attacker initiates an active downgrade attack."
}
CVE-2026-104704: hMailServer DANE TLS Enforcement Failure (HIGH Severity, CVSS: 7.4) | Sceawere