CVE-2026-104660

Source
https://cve.org/CVERecord?id=CVE-2026-104660
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104660.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-104660
Published
2026-10-08T10:52:50Z
Modified
2026-10-10T02:47:26Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Missing Authorization in hMailServer
Details

Missing authorization on COM objects in Progressive Robot hMailServer 6.0.0 through 6.3.5 (Windows only) lets a local interactive user with no hMailServer credential read and write arbitrary files as the service account and queue mail as any sender. The service registers its COM classes with no DCOM access or launch permission and calls CoInitializeSecurity with no security descriptor, so any user logged on at the console or over Remote Desktop can activate the classes in the running service; a hMailServer.Message, its Attachments and Attachment, and a hMailServer.FetchAccount created this way carry a credential that never authenticated. Attachments.Add(path) and Attachment.SaveAs(path) performed no authorization check, and Message.Save/Copy and FetchAccount.AccountID/Save performed none either up to 6.3.3 and from 6.3.4 treated a holder with no credential as the server's own event-script host. Because the service does not impersonate the COM caller, Attachments.Add reads any file the service account can read and returns it, Attachment.SaveAs writes attacker-chosen bytes to any path it can write (on a LocalSystem installation, code execution as SYSTEM), Message.Save queues outbound mail from any address past the SMTP checks, and FetchAccount attaches a mail-fetch job to any mailbox. The objects an Application handed out behave the same once a later Authenticate on that Application fails.

Database specific
{
    "cna_assigner": "GitLab",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104660.json"
}
References

Affected packages

Git / gitlab.com/hmailserver/hmailserver

Affected ranges

Type
GIT
Repo
https://gitlab.com/hmailserver/hmailserver
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "6.0.0"
        },
        {
            "fixed": "6.3.6"
        },
        {
            "fixed": "6.3.5"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

Other
build-inputs-1
v6.*
v6.0.0
v6.0.0-B3
v6.0.0-B4
v6.1.0
v6.2.0
v6.2.1
v6.2.10
v6.2.11
v6.2.12
v6.2.13
v6.2.14
v6.2.15
v6.2.16
v6.2.17
v6.2.18
v6.2.19
v6.2.2
v6.2.20
v6.2.21
v6.2.22-pre1
v6.2.22-pre2
v6.2.22-pre3
v6.2.22-pre4
v6.2.22-pre5
v6.2.22-pre6
v6.2.23-alpha1
v6.2.23-alpha2
v6.2.24
v6.2.25
v6.2.26
v6.2.27
v6.2.28
v6.2.3
v6.2.4
v6.2.5
v6.2.6
v6.2.7
v6.2.8
v6.2.9
v6.3.0
v6.3.1
v6.3.2
v6.3.3
v6.3.4
v6.3.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104660.json"