Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to hMailServer 6.3.6, whose helper takes the unit and the AppImage only from its own root-owned command line, refuses an AppImage request where that names none, confirms that the server has stopped, and verifies, runs and installs only copies it made after the stop, readable by root alone until they have verified. Install 6.3.6 with the package manager (apt or dnf) rather than through the live update. An AppImage run under the path unit keeps the helper script copied to /usr/lib/hmailserver/ when its update units were installed, which the AppImage's own update does not replace: copy 6.3.6's script there and give it --image in a drop-in for hmailserver-update.service. Until then: systemctl disable --now hmailserver-update.path, which turns the apply off while the update check and download go on. Windows, builds with -DHM_LIVE_UPDATE=OFF and the container image are not affected.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit. | |
| Title | Reliance on Untrusted Inputs in a Security Decision in hMailServer | |
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T17:35:46.645Z
Reserved: 2026-10-02T07:38:54.248Z
Link: CVE-2026-104658
No data.
Status : Received
Published: 2026-10-08T11:16:43.870
Modified: 2026-10-08T11:16:43.870
Link: CVE-2026-104658
No data.
OpenCVE Enrichment
Updated: 2026-10-08T12:45:18Z
-
CWE-807
Reliance on Untrusted Inputs in a Security Decision