---
id: CVE-2026-107573
title: >-
  Incorrect default permissions in the Windows installer of Progressive Robot
  hMailServer 6.0.0 through 6.3.5 allow a local authenticated user to read the
  mail server's data
summary: >-
  Incorrect default permissions in the Windows installer of Progressive Robot
  hMailServer 6.0.0 through 6.3.5 allow a local authenticated user to read the
  mail server's data. The installer created the data, log, temp, database and
  event fo…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-276
vendor: Progressive Robot Ltd
product: hMailServer
affected:
  - hMailServer >= 6.0.0 < 6.3.6
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:02:43.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107573'
references:
  - url: 'https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6'
    label: cve@gitlab.com
  - url: 'https://gitlab.com/hmailserver/hmailserver/-/work_items/77'
    label: cve@gitlab.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T14:16:23.670041Z'
ingestedAt: '2026-10-08T12:39:48.754Z'
---

## Overview

Incorrect default permissions in the Windows installer of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a local authenticated user to read the mail server's data. The installer created the data, log, temp, database and event folders and the hMailServer.INI configuration file with the permissions inherited from the installation folder, by default under Program Files, which give the local Users group read access. Any user who can sign in to the computer could read every stored message, the logs, the built-in database with the accounts' password hashes whenever the service is stopped, and the configuration file, including the database password, which is sealed only with the machine's DPAPI key and can be unsealed by any local account; with an external database that password gives full control of it. The Linux AppImage of 6.3.0 through 6.3.5 likewise created its per-user data folders readable by other local users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
