---
id: CVE-2026-104658
title: >-
  The Linux live-update apply helper (hmailserver-update) of Progressive Robot
  hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the
  unprivileged hmailserver service account, and took from that request the
  program used …
summary: >-
  The Linux live-update apply helper (hmailserver-update) of Progressive Robot
  hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the
  unprivileged hmailserver service account, and took from that request the
  program used …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-807
vendor: Progressive Robot Ltd
product: hMailServer
affected:
  - hMailServer >= 6.3.4 < 6.3.6
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T18:17:13.503'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104658'
references:
  - url: 'https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6'
    label: cve@gitlab.com
  - url: 'https://gitlab.com/hmailserver/hmailserver/-/work_items/58'
    label: cve@gitlab.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T17:35:35.801848Z'
ingestedAt: '2026-10-08T11:31:27.689Z'
---

## Overview

The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
