Sceawere

Vulnerability Detail

CVE-2026-107573UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Insecure Default Permissions in hMailServer

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
2h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-276: Incorrect Default Permissions
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Incorrect default permissions in the Windows installer of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a local authenticated user to read the mail server's data. The installer created the data, log, temp, database and event folders and the hMailServer.INI configuration file with the permissions inherited from the installation folder, by default under Program Files, which give the local Users group read access. Any user who can sign in to the computer could read every stored message, the logs, the built-in database with the accounts' password hashes whenever the service is stopped, and the configuration file, including the database password, which is sealed only with the machine's DPAPI key and can be unsealed by any local account; with an external database that password gives full control of it. The Linux AppImage of 6.3.0 through 6.3.5 likewise created its per-user data folders readable by other local users.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-10-08T12:17:15.027Z",
  "pubdate": "2026-10-08T12:17:15.027Z",
  "executiveSummary": "The hMailServer software, specifically versions 6.0.0 through 6.3.5 for Windows and 6.3.0 through 6.3.5 for the Linux AppImage, contains a critical security misconfiguration related to improper access control lists (ACLs) on sensitive installation directories.\nThe vulnerability stems from the installer's failure to explicitly restrict permissions on the data, log, temp, database, and configuration folders, causing them to inherit permissive ACLs from the Program Files parent directory.\nBy default, these folders grant read access to the local 'Users' group, allowing any authenticated local user to access sensitive mail server data.\nThis creates a high-risk security posture where any user with local login capabilities can compromise the confidentiality of all stored emails, system logs, and account credentials.\nFurthermore, the exposure of the hMailServer.INI configuration file allows for the extraction of database credentials. In environments utilizing external databases, this risk escalates to full database compromise.\nExploitation requires local authentication on the host system but does not require administrative privileges, significantly lowering the barrier for unauthorized data access and lateral privilege escalation.",
  "technicalDetails": "The root cause of this vulnerability is improper handling of filesystem permissions during the installation process of hMailServer. By default, the installer deploys the application and its critical subdirectories (data, log, temp, database, and event folders) within 'Program Files'. Because these subdirectories inherit the ACLs of the parent directory, they grant the local 'Users' group read access, violating the principle of least privilege.\nThe configuration file, 'hMailServer.INI', is also subject to these insecure inheritance rules. This file contains sensitive information, including credentials for external database backends. While the database password is protected via the Windows Data Protection API (DPAPI), this protection is insufficient in this context; since DPAPI secrets are tied to the machine context (Machine Key), any local authenticated user can invoke the necessary decryption routines to unseal the credentials. This allows an attacker to gain full administrative control over the backend database server.\nThe exploitation flow proceeds as follows: First, an attacker with low-privileged access to the local machine identifies the hMailServer installation path. Second, due to the inherited read permissions on the data directory, the attacker can traverse the file structure to locate stored mail messages and log files, facilitating the exfiltration of sensitive communications and metadata. Third, the attacker accesses 'hMailServer.INI' to extract the encrypted database password. Fourth, the attacker uses local system utilities or custom scripts to programmatically unseal the DPAPI-encrypted password. Fifth, if an external database is configured, the attacker uses the retrieved credentials to authenticate to the database server, potentially gaining full read/write access to user accounts, password hashes, and the entirety of the email store.\nIn the Linux context, the AppImage for versions 6.3.0 through 6.3.5 similarly fails to restrict access to per-user data folders, allowing other local users to browse the content of these directories. This indicates a consistent failure to apply adequate file permission modes (such as 0700 or equivalent restrictive ACLs) during folder creation across different platforms.\nThe post-exploitation impact is severe, resulting in total loss of confidentiality for all hosted email accounts, exposure of password hashes facilitating offline brute-force attacks, and potential database takeover."
}
CVE-2026-107573: Insecure Default Permissions in hMailServer (HIGH Severity, CVSS: 7.8) | Sceawere