Skip to main content

CVE-2026-107573: CWE-276: Incorrect Default Permissions in Progressive Robot Ltd hMailServer

0
High
VulnerabilityCVE-2026-107573cvecve-2026-107573cwe-276
Published: 10/08/2026 (10/08/2026, 11:46:31 UTC)
Source: CVE Database V5
Vendor/Project: Progressive Robot Ltd
Product: hMailServer

Description

Incorrect default permissions in the Windows installer of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a local authenticated user to read the mail server's data. The installer created the data, log, temp, database and event folders and the hMailServer.INI configuration file with the permissions inherited from the installation folder, by default under Program Files, which give the local Users group read access. Any user who can sign in to the computer could read every stored message, the logs, the built-in database with the accounts' password hashes whenever the service is stopped, and the configuration file, including the database password, which is sealed only with the machine's DPAPI key and can be unsealed by any local account; with an external database that password gives full control of it. The Linux AppImage of 6.3.0 through 6.3.5 likewise created its per-user data folders readable by other local users.

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

Progressive Robot Ltd

hMailServer

Affected versions
>=6.0.0 <6.3.6
GitHub Actionsmore threats →ai
hmailserver/hmailserver
pkg:github/hmailserver/hmailserver
Affected versions
>=6.0.0 <6.3.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 12:18:45 UTC

Technical Analysis

The vulnerability arises from incorrect default permissions set by the Windows installer of hMailServer versions 6.0.0 through 6.3.5. The installer creates data, log, temp, database, and event folders, as well as the hMailServer.INI configuration file, inheriting permissions from the installation folder under Program Files, which grants read access to the local Users group. Consequently, any local authenticated user can read all stored messages, logs, the built-in database containing password hashes (when the service is stopped), and the configuration file including the database password. The database password is protected only by the machine's DPAPI key, which any local user can unseal. For installations using an external database, this password grants full control over the database. Similarly, the Linux AppImage versions 6.3.0 through 6.3.5 create per-user data folders that are readable by other local users, exposing sensitive data.

Potential Impact

Local authenticated users can read sensitive data including all stored emails, logs, password hashes, and configuration files containing database credentials. This can lead to unauthorized disclosure of confidential information and potential full control over the mail server's database if an external database is used. The vulnerability affects confidentiality, integrity, and availability as indicated by the CVSS vector.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict local user access to the installation directories and data folders by manually adjusting permissions to prevent unauthorized read access. Consider running the service under a dedicated user account with minimal privileges and isolating the server environment to limit local user access.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitLab
Date Reserved
2026-10-08T10:51:30.642Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac786ba2cdf04f65611bbb7

Added to database: 10/08/2026, 12:04:10 UTC

Last enriched: 10/08/2026, 12:18:45 UTC

Last updated: 10/08/2026, 15:04:12 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses