Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107573— Incorrect Default Permissions in hMailServer

Quick assessment

Affected
Progressive Robot Ltd hMailServer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Progressive Robot hMailServer 6.0.0 至 6.3.5 版本的 Windows 安装程序存在默认权限配置错误,导致本地已认证用户可以读取邮件服务器数据。安装程序在默认情况下(位于 Program Files 目录下)创建了数据、日志、临时、数据库和事件文件夹以及 hMailServer.INI 配置文件,并继承自安装文件夹的权限设置,允许本地“用户”组具有读取访问权限。任何能够登录计算机的用户都可以在服务停止时读取所有存储的邮件、日志、内置数据库(包含账户密码哈希)以及配置文件(包括

CVSS 7.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107573

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Incorrect Default Permissions in hMailServer
Source: CVE Program / CVE List V5
Vulnerability Description
Incorrect default permissions in the Windows installer of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a local authenticated user to read the mail server's data. The installer created the data, log, temp, database and event folders and the hMailServer.INI configuration file with the permissions inherited from the installation folder, by default under Program Files, which give the local Users group read access. Any user who can sign in to the computer could read every stored message, the logs, the built-in database with the accounts' password hashes whenever the service is stopped, and the configuration file, including the database password, which is sealed only with the machine's DPAPI key and can be unsealed by any local account; with an external database that password gives full control of it. The Linux AppImage of 6.3.0 through 6.3.5 likewise created its per-user data folders readable by other local users.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
缺省权限不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Progressive Robot Ltd hMailServer 6.0.0 ~ 6.3.6 -

II. Public POCs for CVE-2026-107573

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107573

请登录查看更多情报信息。

Other References for CVE-2026-107573 (2)

Same Patch Batch · Progressive Robot Ltd · 2026-10-08 · 24 CVEs total

CVE-2026-103647 8.0 HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hM
CVE-2026-103010 7.8 HIGH Heap-based Buffer Overflow in hMailServer
CVE-2026-104660 7.8 HIGH Missing Authorization in hMailServer
CVE-2026-104658 7.8 HIGH Reliance on Untrusted Inputs in a Security Decision in hMailServer
CVE-2026-107576 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107577 7.5 HIGH Loop with Unreachable Exit Condition ('Infinite Loop') in hMailServer
CVE-2026-107574 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107579 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-104659 7.5 HIGH Origin Validation Error in hMailServer
CVE-2026-103649 7.5 HIGH Synchronous Access of Remote Resource without Timeout in hMailServer
CVE-2026-107584 7.4 HIGH Not Failing Securely ('Failing Open') in hMailServer
CVE-2026-104704 7.4 HIGH Cleartext Transmission of Sensitive Information in hMailServer
CVE-2026-107578 6.7 MEDIUM Improper Link Resolution Before File Access ('Link Following') in hMailServer
CVE-2026-107583 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107572 6.5 MEDIUM Inefficient Regular Expression Complexity in hMailServer
CVE-2026-107581 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107582 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107580 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-103011 6.5 MEDIUM Heap-based Buffer Overflow in hMailServer
CVE-2026-107587 5.9 MEDIUM Improper Certificate Validation in hMailServer

Showing top 20 of 24 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-107573

No comments yet


Leave a comment