PT-2026-99509 · Unknown · Hmailserver

CVE-2026-100741

·

Published

2026-09-27

·

Updated

2026-10-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions hMailServer versions 6.0.0 through 6.3.3
Description An eval injection exists in the JScript event-script dispatcher on Windows. A remote, unauthenticated attacker can execute arbitrary JScript within the service process using the privileges of the service account. This occurs when a password containing a backslash followed by an apostrophe is sent during a logon attempt (SMTP AUTH, POP3, or IMAP) for an existing active account. The issue stems from the server writing event values into handler calls as JScript string literals, escaping apostrophes but failing to escape backslashes, which allows the literal to be closed and subsequent text to be parsed as script.
Exploitation requires a non-default configuration where event scripting is enabled, the script language is set to JScript, and a specific handler is defined. Vulnerable handlers include OnClientValidatePassword(), OnExternalAccountDownload() (via POP3 server message UID), and OnDeliveryFailed() (via SMTP server error reply). Depending on the version and the ScriptAllowedObjects value, an attacker may create COM objects, such as WScript.Shell, to achieve OS command execution.
Recommendations Update hMailServer to version 6.3.4 or later. As a temporary mitigation, disable event scripting or change the script language from JScript to VBScript. Restrict the use of the OnClientValidatePassword(), OnExternalAccountDownload(), and OnDeliveryFailed() handlers until the update is applied.

Fix

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100741

Affected Products

Hmailserver