PT-2026-99509 · Unknown · Hmailserver
CVE-2026-100741
·
Published
2026-09-27
·
Updated
2026-10-04
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
hMailServer versions 6.0.0 through 6.3.3
Description
An eval injection exists in the JScript event-script dispatcher on Windows. A remote, unauthenticated attacker can execute arbitrary JScript within the service process using the privileges of the service account. This occurs when a password containing a backslash followed by an apostrophe is sent during a logon attempt (SMTP AUTH, POP3, or IMAP) for an existing active account. The issue stems from the server writing event values into handler calls as JScript string literals, escaping apostrophes but failing to escape backslashes, which allows the literal to be closed and subsequent text to be parsed as script.
Exploitation requires a non-default configuration where event scripting is enabled, the script language is set to JScript, and a specific handler is defined. Vulnerable handlers include
OnClientValidatePassword(), OnExternalAccountDownload() (via POP3 server message UID), and OnDeliveryFailed() (via SMTP server error reply). Depending on the version and the ScriptAllowedObjects value, an attacker may create COM objects, such as WScript.Shell, to achieve OS command execution.Recommendations
Update hMailServer to version 6.3.4 or later.
As a temporary mitigation, disable event scripting or change the script language from JScript to VBScript.
Restrict the use of the
OnClientValidatePassword(), OnExternalAccountDownload(), and OnDeliveryFailed() handlers until the update is applied.Fix
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hmailserver