Sceawere

Vulnerability Detail

CVE-2026-107587UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer Improper S/MIME Certificate Validation

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
2h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-295: Improper Certificate Validation
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Improper certificate validation in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to have S/MIME-encrypted mail that the account later sends to another correspondent also encrypted to the attacker's key. When its recipient opened a signed message, the webmail kept the signer's certificate for encrypting replies whether or not the server found its chain trusted, under the first e-mail address the certificate listed rather than the message's From address, and beside any certificate already held for that address. Encrypted mail later sent from the webmail to that address was encrypted to every certificate held for it, so a holder of the kept certificate's key who obtains a copy of such a message can read it.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-10-08T12:17:16.937Z",
  "pubdate": "2026-10-08T12:17:16.937Z",
  "executiveSummary": "This vulnerability involves improper S/MIME certificate validation within the webmail component of Progressive Robot hMailServer versions 6.3.2 through 6.3.5.\nThe flaw allows a remote, unauthenticated attacker to manipulate the certificate storage mechanism of the webmail interface.\nBy sending a signed message to a target, an attacker can force the application to ingest and store a malicious certificate, regardless of the validity of the certificate's trust chain.\nThe system erroneously associates this certificate with the recipient's email address and adds it to the existing certificate pool for that address.\nConsequently, future S/MIME-encrypted communications sent from the webmail to that address are encrypted using the attacker's public key alongside legitimate keys.\nThis results in a critical loss of confidentiality, as the attacker can decrypt sensitive correspondence intercepted from the targeted user.\nThe vulnerability represents a significant risk to data privacy, as it enables passive decryption of encrypted messages without the sender's awareness or explicit consent.",
  "technicalDetails": "The root cause of this vulnerability lies in the insecure handling of S/MIME certificates during the message signature verification process within the hMailServer webmail component.\nWhen a user opens a signed message, the webmail interface automatically extracts the signer's certificate. The logic fails to enforce verification of the certificate's trust chain, meaning any provided certificate is accepted as valid by the application.\nFurthermore, the association logic is flawed: the application maps the imported certificate to the first email address listed within the certificate attributes rather than validating it against the 'From' address of the original email message. This allows for cross-address certificate injection.\nOnce the malicious certificate is ingested, the webmail component stores it in the local certificate database for the associated email address, appending it to the collection of existing, potentially legitimate certificates.\nThe attack flow proceeds as follows: First, the attacker sends an S/MIME-signed email to the victim. The attacker includes a malicious certificate with their own public key, potentially aliased to a target recipient's address. Second, when the victim's webmail client processes this message, it improperly trusts and stores the attacker's certificate, linking it to the victim's address record.\nThird, when the victim (or the webmail system) attempts to send an encrypted reply or a new encrypted message to the forged address, the system iterates through all stored certificates for that recipient. It performs multi-recipient encryption, encrypting the message payload for each certificate held in the store, including the attacker's.\nBecause the message is encrypted using the attacker's public key, the attacker—possessing the corresponding private key—can intercept and decrypt the message content.\nThe vulnerability affects hMailServer webmail in versions 6.3.2 through 6.3.5. Exploitation does not require prior authentication to the server, as the trigger is the processing of an incoming email message, making the attack surface the inbound mail processing pipeline. The impact is a complete bypass of S/MIME confidentiality guarantees, enabling persistent and silent eavesdropping on future encrypted communications involving the victim."
}
CVE-2026-107587: hMailServer Improper S/MIME Certificate Validation (MEDIUM Severity, CVSS: 5.9) | Sceawere