---
id: CVE-2026-107578
title: >-
  Improper link resolution and external control of file paths in the
  administrative command-line operations of hMailServer.exe in Progressive Robot
  hMailServer 6.3.4 and 6.3.5 allow a local attacker who already runs code as
  the low-privile…
summary: >-
  Improper link resolution and external control of file paths in the
  administrative command-line operations of hMailServer.exe in Progressive Robot
  hMailServer 6.3.4 and 6.3.5 allow a local attacker who already runs code as
  the low-privile…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-59
vendor: Progressive Robot Ltd
product: hMailServer
affected:
  - hMailServer >= 6.3.4 < 6.3.6
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T15:17:44.057'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107578'
references:
  - url: 'https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6'
    label: cve@gitlab.com
  - url: 'https://gitlab.com/hmailserver/hmailserver/-/work_items/71'
    label: cve@gitlab.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T14:17:49.322792Z'
ingestedAt: '2026-10-08T12:39:48.756Z'
---

## Overview

Improper link resolution and external control of file paths in the administrative command-line operations of hMailServer.exe in Progressive Robot hMailServer 6.3.4 and 6.3.5 allow a local attacker who already runs code as the low-privilege service account to escalate privilege. On Windows, operations run with administrator rights by the installer, DBSetup, the Control Panel or an administrator wrote log entries and crash records into the log folder, created, deleted and changed the permissions of the self-signed certificate and private key in the data folder, and rewrote message files in the data folder, all by path in folders the service account (NT SERVICE\hMailServer, the default for new installations since 6.3.4) can modify, following junctions and mount points; and the store-maintenance operations reached files by names taken from the database, which the service account can write, including names outside the data folder. On Linux, the store-maintenance and object-storage operations run as root followed symbolic links the service account (the packaged hmailserver user, which owns the data folder) planted in it, so a root-run operation read, wrote or removed the link's target as root. A local attacker controlling the service account can thereby gain the administrator's (Windows) or root's (Linux) privileges when such an operation is run.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
