Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to hMailServer 6.3.6, whose REST listener refuses an unexpected Host before any authentication and delays a wrong administrator password on every route. Until then: keep the REST API off (RestApiPort 0, the default) or reach it only through a reverse proxy that checks the Host header; give the administrator a long random password and enrol its second factor; do not browse the web from the server.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Host header validation and missing throttling of failed administrator sign-ins in the REST API listener of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote attacker to brute-force the server administrator's password through the administrator's own browser by DNS rebinding. The listener, which is off by default and bound to the loopback when enabled, answered requests whatever their Host header named, and a failed sign-in with the administrator's password from the loopback was neither auto-banned nor delayed. A web page whose host name the attacker rebinds to 127.0.0.1, opened in a browser on the server, can therefore send authenticated requests to the listener, read the answers and try administrator passwords at full speed until one is accepted, giving the attacker full administrative control of the mail server. | |
| Title | Origin Validation Error in hMailServer | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T14:24:55.631Z
Reserved: 2026-10-02T07:38:59.115Z
Link: CVE-2026-104659
Updated: 2026-10-08T14:24:51.276Z
Status : Received
Published: 2026-10-08T11:16:44.013
Modified: 2026-10-08T15:17:32.010
Link: CVE-2026-104659
No data.
OpenCVE Enrichment
Updated: 2026-10-08T12:45:18Z
-
CWE-346
Origin Validation Error