CVE-2026-104659
Received Received - Intake

Missing Host Header Validation and Brute-Force in hMailServer REST API

Vulnerability report for CVE-2026-104659, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Missing Host header validation and missing throttling of failed administrator sign-ins in the REST API listener of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote attacker to brute-force the server administrator's password through the administrator's own browser by DNS rebinding. The listener, which is off by default and bound to the loopback when enabled, answered requests whatever their Host header named, and a failed sign-in with the administrator's password from the loopback was neither auto-banned nor delayed. A web page whose host name the attacker rebinds to 127.0.0.1, opened in a browser on the server, can therefore send authenticated requests to the listener, read the answers and try administrator passwords at full speed until one is accepted, giving the attacker full administrative control of the mail server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects hMailServer versions 6.0.0 to 6.3.5 due to two issues in the REST API. First, the API listener accepted requests regardless of the Host header value, even if it didn't match the expected host. Second, failed administrator password attempts from the loopback address were not throttled or banned, allowing rapid password guessing attempts.

Detection Guidance

Check if the REST API port is enabled by inspecting hMailServer configuration files or logs for RestApiPort settings. Monitor network traffic for unusual requests to localhost or 127.0.0.1 with mismatched Host headers. Test for missing Host header validation by sending requests with invalid Host headers to the REST API endpoint.

Impact Analysis

An attacker could exploit this by using DNS rebinding to trick a browser on the server into treating a malicious host as the local server. The attacker's webpage could then send requests to the REST API, attempting to guess the administrator password without rate limiting. Once guessed, the attacker would gain full administrator access.

Compliance Impact

This vulnerability could lead to unauthorized administrative access to the mail server, potentially exposing sensitive data such as emails, user credentials, or personal information. For GDPR, this may result in unauthorized data processing or breaches, requiring notification under Article 33. For HIPAA, it could compromise protected health information if the server handles such data, violating safeguards under the Security Rule.

Mitigation Strategies

Disable the REST API listener if not needed, as it is off by default. Upgrade to hMailServer version 6.3.6 or later to apply the security fixes. If the API must remain enabled, restrict access via a reverse proxy that validates Host headers. Use a long, random administrator password and enable multi-factor authentication.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104659. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart