Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100741— Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer

Quick assessment

Affected
Progressive Robot Ltd hMailServer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

这段漏洞描述主要涉及 hMailServer 中的代码注入漏洞。以下是该漏洞描述的中文翻译: Progressive Robot Ltd 公司旗下的 hMailServer(Windows 平台,版本 6.0.0 至 6.3.3)中的 JScript 事件脚本调度器存在 Eval 注入漏洞。攻击者可以通过在登录请求(包括 SMTP AUTH、POP3 或 IMAP)中发送包含“反斜杠后跟单引号”的密码,对现有且处于活跃状态的账户进行身份验证,从而在远程、无需认证的情况下,以服务账户权限在 hMailServer 服

CVSS 9.8 · Critical EPSS 1.73% · P77
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100741

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer
Source: CVE Program / CVE List V5
Vulnerability Description
Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password containing a backslash followed by an apostrophe, sent in any logon (SMTP AUTH, POP3, IMAP) that names an existing, active account. Exploitation requires a non-default configuration: event scripting enabled (off by default), the script language set to JScript (the default is VBScript), and an OnClientValidatePassword handler defined in the event script. The server wrote event values into the handler call as JScript string literals, escaping the apostrophe but not the backslash, so such a value closes the literal and the rest of it is parsed as script. The same flaw is reachable by a remote POP3 server through the message UID it returns, where an OnExternalAccountDownload handler is defined, and by a remote SMTP server through the error reply it rejects a delivery with, where an OnDeliveryFailed handler is defined. Before 6.2.25 the injected script can create any COM object, and from 6.2.25 it can with the default ScriptAllowedObjects value of '*'; WScript.Shell among them gives command execution as the service account. VBScript event scripts and the Linux builds of Progressive Robot Ltd's hMailServer are not affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Progressive Robot Ltd hMailServer 6.0.0 ~ 6.3.4 -

II. Public POCs for CVE-2026-100741

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100741

请登录查看更多情报信息。

Other References for CVE-2026-100741 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-100741

No comments yet


Leave a comment