CVE-2026-104704
Received Received - Intake

Opportunistic TLS Downgrade in hMailServer

Vulnerability report for CVE-2026-104704, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Progressive Robot hMailServer 6.0.0 through 6.3.5 does not enforce TLS for outbound SMTP delivery to a mail exchanger whose DNSSEC-validated TLSA records contain no DANE-EE (usage 3) record, contrary to RFC 7672 section 2.2. The server used only DANE-EE records and treated a validated TLSA record set consisting of DANE-TA (usage 2) or otherwise unusable records as if no records were published, so delivery to such a host fell back to opportunistic TLS. An attacker with an active position on the network path between the server and the recipient's mail exchanger can suppress or break the STARTTLS negotiation and cause messages to be delivered in cleartext, where they can be read and modified.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects hMailServer versions 6.0.0 to 6.3.5. When sending emails, the server fails to enforce TLS for domains with DNSSEC-validated TLSA records that lack DANE-EE (usage 3) entries. Instead of enforcing TLS as required by RFC 7672, it falls back to opportunistic TLS, allowing potential interception or alteration of emails by attackers on the network path.

Detection Guidance

To detect this vulnerability, check if your hMailServer version is between 6.0.0 and 6.3.5. Inspect DNSSEC-validated TLSA records for recipient domains to confirm if they lack DANE-EE (usage 3) records. Use tools like dig or nslookup to query TLSA records and verify TLS enforcement settings in SMTP routes.

Impact Analysis

An attacker could intercept or modify emails sent by the server if they gain a position on the network path between the server and the recipient's mail exchanger. This could lead to exposure of sensitive information or tampering with email content.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA, which require protection of personal and health data during transmission. Failure to enforce TLS may result in unauthorized access to sensitive information, violating data protection regulations.

Mitigation Strategies

Upgrade hMailServer to version 6.3.6 or later. Alternatively, configure SMTP routes for affected domains with 'STARTTLS (required)' security to enforce TLS. Ensure recipient domains have proper DNSSEC and DANE-EE records if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104704. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart