Sceawere

Vulnerability Detail

CVE-2026-107578UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer Local Privilege Escalation

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.7
Creation Date
2h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-59: Improper Link Resolution Before File Access ('Link Following')
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Improper link resolution and external control of file paths in the administrative command-line operations of hMailServer.exe in Progressive Robot hMailServer 6.3.4 and 6.3.5 allow a local attacker who already runs code as the low-privilege service account to escalate privilege. On Windows, operations run with administrator rights by the installer, DBSetup, the Control Panel or an administrator wrote log entries and crash records into the log folder, created, deleted and changed the permissions of the self-signed certificate and private key in the data folder, and rewrote message files in the data folder, all by path in folders the service account (NT SERVICE\hMailServer, the default for new installations since 6.3.4) can modify, following junctions and mount points; and the store-maintenance operations reached files by names taken from the database, which the service account can write, including names outside the data folder. On Linux, the store-maintenance and object-storage operations run as root followed symbolic links the service account (the packaged hmailserver user, which owns the data folder) planted in it, so a root-run operation read, wrote or removed the link's target as root. A local attacker controlling the service account can thereby gain the administrator's (Windows) or root's (Linux) privileges when such an operation is run.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.7",
  "pubDate": "2026-10-08T12:17:15.787Z",
  "pubdate": "2026-10-08T12:17:15.787Z",
  "executiveSummary": "Progressive Robot hMailServer versions 6.3.4 and 6.3.5 are susceptible to local privilege escalation due to improper link resolution and inadequate path validation in administrative command-line operations.\nThe vulnerability allows an attacker who has compromised the low-privilege service account to manipulate system file paths, leading to unauthorized file system operations performed with elevated privileges.\nOn Windows, the service account can induce the administrative process to perform arbitrary file modifications, including changing permissions and overwriting critical data files, by utilizing junction points and symbolic links.\nOn Linux, the vulnerability manifests through the exploitation of symbolic links within the data folder, which are followed by root-privileged processes, facilitating arbitrary file read, write, or deletion operations.\nSuccessful exploitation requires the attacker to have pre-existing control over the low-privilege service account used by the hMailServer software.\nThe primary risk implication is the full compromise of the host system, as the attacker can escalate privileges to administrator (Windows) or root (Linux) by weaponizing administrative operations that interact with attacker-controlled directory structures.",
  "technicalDetails": "The core vulnerability stems from a lack of secure file path handling during administrative operations in hMailServer.exe and related maintenance components. The application fails to resolve file paths safely, ignoring the potential for directory traversal or path redirection via symbolic links and junction points.\nOn Windows, the hMailServer service (NT SERVICE\\hMailServer) is configured with write access to its data folder. Administrative operations—typically triggered by installers, DBSetup, or the Control Panel—operate with elevated privileges. Because these operations do not sanitize paths when writing logs, crash records, or certificate files, an attacker can create junction points or mount points within the data directory. When an administrator-level process accesses these paths, the OS follows the junction to arbitrary system locations. This permits the attacker to overwrite critical files, alter file permissions, or corrupt sensitive data structures, effectively enabling privilege escalation.\nFurthermore, store-maintenance operations utilize database-stored file names to conduct operations. Since the service account can modify the database, an attacker can inject malicious paths (e.g., directory traversal strings) that point to files outside the intended data folder. When the administrative maintenance routine executes, it follows these paths, resulting in unintended file manipulation with administrative privileges.\nOn Linux, the vulnerability is a classic race condition or time-of-check to time-of-use (TOCTOU) scenario involving symbolic links. The administrative maintenance and object-storage operations run with root privileges. Because the service account (the 'hmailserver' user) maintains ownership of the data folder, it can plant symbolic links at locations where administrative routines are expected to operate. When the root-level administrative task executes, it dereferences these symbolic links without verifying the target location. Consequently, the root process reads, writes, or deletes files pointed to by the attacker's symbolic links.\nThe attack flow requires the adversary to establish initial access under the hMailServer service account context. Once localized, the attacker prepares the target directory by populating it with malicious links or junctions. The attacker then triggers or waits for a scheduled administrative maintenance task or system crash, which causes the privileged process to execute operations on the manipulated paths. The post-exploitation result is the attainment of full administrative or root control over the host operating system."
}
CVE-2026-107578: hMailServer Local Privilege Escalation (MEDIUM Severity, CVSS: 6.7) | Sceawere