CVE-2026-104704: CWE-319: Cleartext Transmission of Sensitive Information in Progressive Robot Ltd hMailServer
Description
Progressive Robot Ltd's hMailServer versions 6.0.0 through 6.3.5 do not properly enforce TLS for outbound SMTP delivery when DNSSEC-validated TLSA records lack a DANE-EE (usage 3) record. Instead, the server treats certain TLSA record sets as if no records exist, falling back to opportunistic TLS. This behavior allows an active network attacker to suppress or break STARTTLS negotiation, causing emails to be sent in cleartext where they can be intercepted or modified.
CVSS v3.1
Score 7.4high
Affected software
Progressive Robot Ltd
hMailServer
pkg:github/hmailserver/hmailserverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104704 describes a vulnerability in Progressive Robot Ltd's hMailServer versions 6.0.0 through 6.3.5 where the server does not enforce TLS for outbound SMTP delivery to mail exchangers whose DNSSEC-validated TLSA records do not contain a DANE-EE (usage 3) record, contrary to RFC 7672 section 2.2. The server only recognizes DANE-EE records and treats validated TLSA record sets containing DANE-TA (usage 2) or other unusable records as if no TLSA records were published. Consequently, delivery to such hosts falls back to opportunistic TLS, which can be downgraded by an attacker with an active network position to cleartext transmission by suppressing or breaking STARTTLS negotiation. This allows interception and modification of email messages in transit.
Potential Impact
An attacker positioned on the network path between the hMailServer and the recipient's mail exchanger can cause outbound emails to be transmitted without encryption by interfering with the STARTTLS negotiation. This leads to cleartext transmission of sensitive information, enabling the attacker to read or modify email content. The vulnerability compromises confidentiality and integrity of outbound email messages but does not affect availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should consider alternative mitigations such as enforcing strict TLS policies manually or using external mail gateways that enforce proper DANE validation. Monitoring for updates from Progressive Robot Ltd is recommended.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitLab
- Date Reserved
- 2026-10-02T10:10:21.800Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac778a32cdf04f6560ccf54
Added to database: 10/08/2026, 11:04:03 UTC
Last enriched: 10/08/2026, 11:18:16 UTC
Last updated: 10/08/2026, 11:19:29 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.