VYPR
advisoryPublished Oct 8, 2026· Updated Oct 9, 2026· 1 source

hMailServer: 18 Vulnerabilities Disclosed Together, Exploiting DoS and Privilege Escalation Flaws

Key findings • 18 vulnerabilities disclosed for hMailServer on October 8, 2026, affecting versions 6.0.0 through 6.3.5. • Multiple denial-of-service vulnerabilities exist due to inefficient a…

Key findings

  • 18 vulnerabilities disclosed for hMailServer on October 8, 2026, affecting versions 6.0.0 through 6.3.5.
  • Multiple denial-of-service vulnerabilities exist due to inefficient algorithmic complexity in mail processing functions.
  • High-severity flaws include privilege escalation, unauthorized file access, and potential disruption of authentication mechanisms.
  • Vulnerabilities are present in the REST API, webmail, IMAP, SMTP, and installer components.
  • Prompt patching is essential to mitigate risks of service unavailability and unauthorized access.

On October 8, 2026, a significant batch of 18 vulnerabilities was disclosed for Progressive Robot's hMailServer, affecting versions 6.0.0 through 6.3.5. These vulnerabilities, disclosed within a four-hour window, span a range of severity, with several rated as High, and impact various components including the REST API, webmail, IMAP, SMTP, and the installer. The disclosures highlight potential denial-of-service (DoS) conditions, privilege escalation, and authentication bypasses, underscoring the need for prompt patching.

Several vulnerabilities stem from inefficient algorithmic complexity, leading to potential denial-of-service conditions. CVE-2026-107583, CVE-2026-107582, and CVE-2026-107581 detail how crafted messages or IMAP commands can consume excessive server resources, making webmail, administration consoles, and REST APIs unavailable. Similarly, CVE-2026-107576 describes a DoS vulnerability in inbound DKIM and ARC signature verification, while CVE-2026-103649 points to missing network timeouts in Linux builds that can halt outbound mail delivery. CVE-2026-107575 also contributes to DoS through inefficient SPF macro expansion.

High-severity flaws include privilege escalation and unauthorized access. CVE-2026-107573 details incorrect default permissions in the Windows installer, allowing local authenticated users to read sensitive mail server data. CVE-2026-107578 describes improper link resolution and external control of file paths in administrative command-line operations, enabling local privilege escalation for attackers already running as the service account. On Linux, CVE-2026-104658 highlights a vulnerability in the live-update apply helper that could allow an unprivileged user to execute arbitrary code as root.

Authentication and session management are also impacted. CVE-2026-104659 allows remote attackers to brute-force the administrator password via DNS rebinding due to missing Host header validation and throttling of failed sign-ins in the REST API. CVE-2026-107585 enables remote unauthenticated attackers to disrupt OpenID Connect, SAML, and passkey sign-ins due to uncontrolled eviction in pending sign-in tables. CVE-2026-107586 permits remote authenticated users to end other users' sessions via uncontrolled eviction in the browser session table of the REST API.

Further impacting security are issues with certificate validation and protocol enforcement. CVE-2026-107587 involves improper certificate validation in webmail, potentially allowing attackers to intercept S/MIME encrypted mail. CVE-2026-107584 and CVE-2026-104704 highlight failures in DANE (RFC 7672) validation for outbound SMTP delivery, where the server does not properly enforce TLS when DNSSEC validation fails or when specific DANE records are absent.

Cross-site scripting remains a concern, with CVE-2026-103647 detailing an XSS vulnerability in webmail that allows remote attackers to execute scripts in the context of a user's session when they receive an S/MIME or OpenPGP encrypted message. Heap-based buffer overflows are also present: CVE-2026-103010 and CVE-2026-103011 describe vulnerabilities in legacy Blowfish encryption and decryption routines, respectively, which can lead to denial of service (service crash) and potentially other impacts for authenticated mailbox users or local interactive users.

The vulnerabilities affect hMailServer versions from 6.0.0 through 6.3.5. Users are strongly advised to update to the latest available version to mitigate these risks. The broad range of affected versions and the diverse nature of the vulnerabilities emphasize the critical need for administrators to review and apply patches promptly to protect against potential service unavailability, unauthorized access, and data breaches.

Vypr Intelligence reported on this batch, noting the significant number of DoS vulnerabilities and other high-severity flaws. They highlighted that the vulnerabilities span multiple services and components, reinforcing the urgency of patching.

Vypr Intelligence

Synthesized by Vypr AI