CVE-2026-107586
Received Received - Intake

Session Hijacking in hMailServer via Uncontrolled Eviction

Vulnerability report for CVE-2026-107586, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Uncontrolled eviction in the browser session table of the REST API in Progressive Robot hMailServer 6.2.28 through 6.3.5 allows a remote authenticated user to end other users' sessions. The table of browser sessions, shared by every account, the server administrator and support sessions, dropped its least recently used session whenever it was full, whoever it belonged to, and placed no limit on how many sessions one account could hold. A user who repeatedly signs in with their own mailbox password can therefore keep the table full and sign out every webmail and administration session that is idle for more than a short time, for as long as they continue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.2.28

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in hMailServer 6.2.28 through 6.3.5 allows a remote authenticated user to forcibly end other users' sessions by filling a shared browser session table. The table evicts the least recently used sessions when full, regardless of ownership, enabling an attacker to keep the table full by repeatedly signing in. This disrupts access to webmail and administration interfaces for idle sessions.

Detection Guidance

Monitor for unusual session evictions in hMailServer logs, particularly for webmail or administration sessions being forcibly logged out after inactivity. Check for repeated authentication attempts from the same account via the REST API.

Impact Analysis

If you are a user of hMailServer versions 6.2.28 to 6.3.5, an attacker with your credentials could repeatedly log in to fill the session table, causing your idle webmail or admin sessions to be logged out. This disrupts your access to the web interface until you log in again. The impact is limited to web surface availability and does not affect mail protocols.

Compliance Impact

This vulnerability could impact compliance by disrupting access to critical web interfaces, potentially leading to unauthorized session termination and reduced availability of services. This may affect data access controls and audit logging, which are important for GDPR and HIPAA compliance. However, the direct impact depends on the specific compliance requirements and mitigations in place.

Mitigation Strategies

Upgrade to hMailServer version 6.3.6 or later to apply the session limit fix. As a temporary measure, rate-limit REST API requests or disable accounts exhibiting abusive behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107586. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart