CVE-2026-107573
Received Received - Intake

Incorrect Default Permissions in hMailServer Windows Installer Allow Local Privilege Escalation

Vulnerability report for CVE-2026-107573, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Incorrect default permissions in the Windows installer of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a local authenticated user to read the mail server's data. The installer created the data, log, temp, database and event folders and the hMailServer.INI configuration file with the permissions inherited from the installation folder, by default under Program Files, which give the local Users group read access. Any user who can sign in to the computer could read every stored message, the logs, the built-in database with the accounts' password hashes whenever the service is stopped, and the configuration file, including the database password, which is sealed only with the machine's DPAPI key and can be unsealed by any local account; with an external database that password gives full control of it. The Linux AppImage of 6.3.0 through 6.3.5 likewise created its per-user data folders readable by other local users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-276 During installation, installed file permissions are set to allow anyone to modify those files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107573 is an incorrect default permissions issue in hMailServer 6.0.0 through 6.3.5. The Windows installer creates folders and files with permissions inherited from Program Files, allowing any local user to read sensitive data like emails, logs, and database passwords. On Linux AppImage, folders are created with overly permissive permissions.

Detection Guidance

Check Windows folders under %ProgramFiles%\hMailServer for inherited 'Users Read' permissions using icacls. For Linux AppImage, verify ~/.local/share/hmailserver folder permissions with ls -ld. Look for sensitive files like hMailServer.INI, database files, or logs accessible by non-admin users.

Impact Analysis

Any local authenticated user can access stored messages, logs, and the built-in database containing account passwords and secrets. If an external database is used, the exposed password could grant full control of it. Attackers could read emails, modify configurations, or escalate privileges.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to sensitive data like emails and personal information. It exposes confidential communications and user credentials, leading to potential data breaches and non-compliance with privacy regulations.

Mitigation Strategies

Upgrade to hMailServer 6.3.6 or later. For Windows, run 'hMailServer.exe /ProtectFolders' to fix permissions. Alternatively, use icacls to remove inherited permissions from affected folders. For Linux AppImage, run 'chmod 0700 ~/.local/share/hmailserver'. Change database and admin passwords if exposed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107573. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart