CVE-2026-107573: CWE-276: Incorrect Default Permissions in Progressive Robot Ltd hMailServer
Description
Incorrect default permissions in the Windows installer of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a local authenticated user to read the mail server's data. The installer created the data, log, temp, database and event folders and the hMailServer.INI configuration file with the permissions inherited from the installation folder, by default under Program Files, which give the local Users group read access. Any user who can sign in to the computer could read every stored message, the logs, the built-in database with the accounts' password hashes whenever the service is stopped, and the configuration file, including the database password, which is sealed only with the machine's DPAPI key and can be unsealed by any local account; with an external database that password gives full control of it. The Linux AppImage of 6.3.0 through 6.3.5 likewise created its per-user data folders readable by other local users.
CVSS v3.1
Score 7.8high
Affected software
Progressive Robot Ltd
hMailServer
pkg:github/hmailserver/hmailserverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from incorrect default permissions set by the Windows installer of hMailServer versions 6.0.0 through 6.3.5. The installer creates data, log, temp, database, and event folders, as well as the hMailServer.INI configuration file, inheriting permissions from the installation folder under Program Files, which grants read access to the local Users group. Consequently, any local authenticated user can read all stored messages, logs, the built-in database containing password hashes (when the service is stopped), and the configuration file including the database password. The database password is protected only by the machine's DPAPI key, which any local user can unseal. For installations using an external database, this password grants full control over the database. Similarly, the Linux AppImage versions 6.3.0 through 6.3.5 create per-user data folders that are readable by other local users, exposing sensitive data.
Potential Impact
Local authenticated users can read sensitive data including all stored emails, logs, password hashes, and configuration files containing database credentials. This can lead to unauthorized disclosure of confidential information and potential full control over the mail server's database if an external database is used. The vulnerability affects confidentiality, integrity, and availability as indicated by the CVSS vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict local user access to the installation directories and data folders by manually adjusting permissions to prevent unauthorized read access. Consider running the service under a dedicated user account with minimal privileges and isolating the server environment to limit local user access.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitLab
- Date Reserved
- 2026-10-08T10:51:30.642Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac786ba2cdf04f65611bbb7
Added to database: 10/08/2026, 12:04:10 UTC
Last enriched: 10/08/2026, 12:18:45 UTC
Last updated: 10/08/2026, 15:04:12 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.