CVE-2026-104658

Source
https://cve.org/CVERecord?id=CVE-2026-104658
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104658.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-104658
Published
2026-10-08T10:52:45Z
Modified
2026-10-10T02:47:21Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Reliance on Untrusted Inputs in a Security Decision in hMailServer
Details

The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.

Database specific
{
    "cna_assigner": "GitLab",
    "cwe_ids": [
        "CWE-807"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104658.json"
}
References

Affected packages

Git / gitlab.com/hmailserver/hmailserver

Affected ranges

Type
GIT
Repo
https://gitlab.com/hmailserver/hmailserver
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "6.3.4"
        },
        {
            "fixed": "6.3.6"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v6.*
v6.3.4
v6.3.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104658.json"