CVE-2026-100741

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password containing a backslash followed by an apostrophe, sent in any logon (SMTP AUTH, POP3, IMAP) that names an existing, active account. Exploitation requires a non-default configuration: event scripting enabled (off by default), the script language set to JScript (the default is VBScript), and an OnClientValidatePassword handler defined in the event script. The server wrote event values into the handler call as JScript string literals, escaping the apostrophe but not the backslash, so such a value closes the literal and the rest of it is parsed as script. The same flaw is reachable by a remote POP3 server through the message UID it returns, where an OnExternalAccountDownload handler is defined, and by a remote SMTP server through the error reply it rejects a delivery with, where an OnDeliveryFailed handler is defined. Before 6.2.25 the injected script can create any COM object, and from 6.2.25 it can with the default ScriptAllowedObjects value of '*'; WScript.Shell among them gives command execution as the service account. VBScript event scripts and the Linux builds of Progressive Robot Ltd's hMailServer are not affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-95

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 2 mentions on most recent observed day (2026-09-28)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-09-27: 1Mentions · 2026-09-28: 209-2709-28
Referenced assets11 URLs
Full discourse3 posts
  • Rıdvan Yağlı@ridvanyagli

    🔴 hMailServer fork'unda kritik RCE açığı: CVE-2026-100741 Progressive Robot Ltd. tarafından geliştirilen hMailServer fork'unda, 6.0.0–6.3.3 Windows sürümlerinde, JScript Event Script Dispatcher'daki Eval Injection açığı uzaktan ve kimlik doğrulaması olmadan kod çalıştırılmasına yol açabiliyor. CVSS: 9.8 Critical Remote Code Execution Authentication gerektirmiyor Etkilenen sürümler: 6.0.0–6.3.3 Yamalanmış sürüm: 6.3.4+ ⚠️ İstismar için Event Scripting'in açık, script dilinin JScript ve ilgili event handler'ın tanımlı olması gerekiyor. Varsayılan yapılandırma bu koşulları sağlamıyor. VBScript event script'leri ve Linux build'leri etkilenmiyor. https://www.progressiverobot.com/hmailserver-downloads/

    00031287
    2.4K followersView on X
  • lee1981@lee1981b

    🔥 CyberForge CVE of the Day #063 🚨 CVE-2026-100741 — hMailServer JScript event-dispatcher Eval Injection → Pre-Auth Remote Code Execution Sometimes the dangerous part is not the protocol parser itself. It is what happens after attacker-controlled protocol data gets turned into executable script text. CVE-2026-100741 affects Progressive Robot Ltd’s hMailServer 6.0.0 through 6.3.3 on Windows. Under specific non-default event-scripting configurations, remotely supplied values can cross from ordinary mail-protocol data into dynamically evaluated JScript, resulting in arbitrary JScript execution inside the hMailServer service process. The flaw carries a CVSS v3.1 score of 9.8 Critical: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H` The important qualifier is configuration: event scripting must be enabled, JScript must be selected, and one of the affected event handlers must be present. Event scripting is off by default and VBScript is the default scripting language. ⚠️ Critical severity does not mean every hMailServer installation is exploitable — but any Windows server using the affected JScript event paths deserves immediate configuration review and upgrade to 6.3.4. 🎯 The quick hit: 🔹 Affected: hMailServer 6.0.0–6.3.3 on Windows. 🔹 Flaw: attacker-controlled values are inserted into dynamically evaluated JScript without correctly neutralising script syntax. 🔹 Impact: arbitrary JScript in the hMailServer service context; permitted COM objects can extend that to operating-system command execution. 🔹 Prerequisites: non-default event scripting + JScript + an affected event handler. 🔹 Fix: upgrade to hMailServer 6.3.4 or later. 🔹 Exploitation: no confirmed in-the-wild exploitation found during today’s review. 🔑 Key details: ⭐ Severity: Critical 📊 CVSS v3.1: 9.8 🧮 Vector: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H` 🧠 Weakness: CWE-95 — Improper Neutralization of Directives in Dynamically Evaluated Code (“Eval Injection”) 🎯 Targets: Progressive Robot Ltd hMailServer 6.0.0–6.3.3 on Windows 🧩 Vulnerable boundary: untrusted mail/event data → JScript string construction → dynamic evaluation 🌐 Attack vector: Network ⚙️ Attack complexity: Low 🔓 Privileges required: None 👆 User interaction: None 🔀 Scope: Unchanged ⚔️ Confirmed impact: arbitrary JScript execution; possible OS command execution through permitted COM objects 💥 CVSS impact: High confidentiality, integrity and availability impact 👤 Execution context: hMailServer service account 🛡️ Fix: upgrade to 6.3.4 or later 🔑 Additional remediation: review event scripting configuration and investigate suspicious authentication/event activity if exposed 🚨 Active exploitation: Not confirmed during this review 🧪 Reproduction: technical mechanics publicly documented; no weaponised reproduction performed by CyberForge 📋 CISA KEV: Not listed at review time 📉 EPSS: current public trackers are not fully consistent; one FIRST-backed tracker reports ~1.73% / ~77th percentile while another currently shows no score — recheck before operational prioritisation 🗓️ Published: 27 September 2026 🩹 Fixed release: 6.3.4 🏷️ Researcher / discovery: reported as identified during hMailServer project code review 🔬 Campaign research: none confirmed 🧬 What actually went wrong? hMailServer supports event scripts that administrators can use to customise behaviour around authentication, external-account downloads, delivery failures and other server events. That flexibility introduces a dangerous trust boundary: protocol data is data — script code is code. The vulnerable dispatcher constructed JScript calls using attacker-influenced event values as string literals. The implementation escaped one special character but failed to correctly account for another escaping condition, meaning crafted input could terminate the intended string context and be interpreted as JScript instead. 1️⃣ Untrusted data enters through a mail workflow One documented path involves authentication attempts through SMTP AUTH, POP3 or IMAP against an existing active account. The attacker does not need to know the account password; the vulnerable behaviour occurs while the configured validation event processes attacker-controlled authentication data. 2️⃣ Event scripting receives the value For this authentication route to be exposed: 🔹 event scripting must be enabled; 🔹 the script language must be JScript; 🔹 an `OnClientValidatePassword` event handler must exist. These are important deployment prerequisites. They prevent us from treating every hMailServer installation as equally exposed. 3️⃣ Data becomes executable script syntax The dispatcher constructs a JScript function invocation using the supplied value. Because escaping is incomplete, specially structured input can break the intended string boundary and alter the script that is evaluated. That is the fundamental failure: an untrusted protocol value crosses into executable language syntax without complete context-aware neutralisation. 4️⃣ JScript executes as the mail service Successful injection executes within the hMailServer service process, inheriting the privileges assigned to that service account. Depending on permitted script objects, arbitrary JScript can also reach operating-system functionality. No weaponised payload, exact injection string or turnkey reproduction recipe is included here. 🧭 It is not only an authentication path. The CVE record describes three separate event contexts capable of reaching the same vulnerable scripting boundary. 🔐 Client authentication. SMTP AUTH, POP3 or IMAP input can reach `OnClientValidatePassword` where the vulnerable configuration exists. 📥 External POP3 account processing. A remote POP3 server can influence a message identifier that reaches an `OnExternalAccountDownload` handler. 📤 Delivery-failure processing. A remote SMTP server can influence an error response passed to an `OnDeliveryFailed` handler. That is a particularly useful defender lesson: one coding weakness may surface through multiple trust boundaries because the vulnerable primitive is shared by several workflows. ⚔️ The practical attack chain: This describes the publicly documented capability rather than providing an exploitation recipe. 1️⃣ An attacker identifies an hMailServer service reachable through SMTP, POP3 or IMAP — or influences one of the documented external mail workflows. 2️⃣ The target is running an affected Windows build between 6.0.0 and 6.3.3. 3️⃣ The relevant non-default JScript event-scripting configuration is enabled. 4️⃣ Attacker-controlled data enters an affected event handler. 5️⃣ The dispatcher incorporates that value into dynamically evaluated JScript. 6️⃣ Incomplete escaping allows the value to alter the intended script context. 7️⃣ Attacker-controlled JScript executes within the hMailServer service process. 8️⃣ Available scripting/COM capabilities determine the practical post-execution blast radius. The vulnerable data-to-code boundary and execution capability come from the published CVE description. Host-impact and hunting recommendations below are CyberForge defender analysis, not evidence of an observed campaign. 👤 Execution context — what does the attacker actually get? This is an important distinction. The vulnerability gives code execution inside the hMailServer service process. That does not automatically mean SYSTEM, domain administrator or total Windows-domain compromise. Actual impact depends on: 🔹 which Windows account runs hMailServer; 🔹 filesystem permissions available to that account; 🔹 accessible configuration and mail data; 🔹 available COM objects; 🔹 stored credentials and integrations; 🔹 outbound network access; 🔹 local privilege boundaries; 🔹 protections around the host. The public description notes that permitted COM objects can provide paths from JScript into operating-system command execution. Earlier affected builds allowed broad COM creation, while newer affected versions can still expose dangerous objects under permissive default `ScriptAllowedObjects` settings. Not automatically established: SYSTEM privileges, credential theft, persistence, lateral movement, ransomware, data exfiltration or domain compromise. Those outcomes require evidence from the affected environment. 📦 Affected products and versions: 🔴 Progressive Robot Ltd hMailServer for Windows Affected: 6.0.0 through 6.3.3 Fixed: 🟢 6.3.4 or later The published record specifically states that Linux builds are not affected by this CVE. It also states that VBScript event scripts are not affected by this JScript-specific flaw. Do not use those exclusions as a reason to postpone inventory. Confirm: 🔹 exact running version; 🔹 operating system; 🔹 whether event scripting is enabled; 🔹 configured scripting language; 🔹 affected handler definitions; 🔹 service account identity; 🔹 internet/network exposure of SMTP, POP3 and IMAP. 👁️ Defender hunting guide. There is currently no confirmed public exploitation campaign for CyberForge to build IOC hunting around, so the sensible approach is behaviour and configuration first. 1️⃣ Establish actual exposure Identify every hMailServer instance running 6.0.0–6.3.3 on Windows. Then determine whether the vulnerable JScript prerequisites existed during the exposure period. A vulnerable version with event scripting disabled is materially different from a server running an affected JScript handler. 2️⃣ Review authentication telemetry Look across SMTP, POP3 and IMAP authentication logs for: 🔍 unusual failed logons against valid accounts; 🔍 malformed or anomalous authentication input; 🔍 concentrated attempts against individual usernames; 🔍 authentication events correlated with server-side process activity. Do not create signatures solely from one literal character sequence. Attackers can alter representation and transport behaviour, and brittle matching creates blind spots. 3️⃣ Review event-script configuration Preserve and examine the actual event scripts and configuration. Determine: 🔹 when JScript was enabled; 🔹 which handlers existed; 🔹 whether those files changed unexpectedly; 🔹 whether script-object permissions were permissive; 🔹 whether configuration drift occurred outside approved change windows. 4️⃣ Correlate hMailServer with Windows process telemetry Investigate unexpected child processes or operating-system activity originating from the hMailServer service. Capture: 🔹 parent process; 🔹 child process; 🔹 command line where available; 🔹 executing account; 🔹 start time; 🔹 network connections; 🔹 created or modified files; 🔹 relevant hashes. The goal is not to assume exploitation — it is to identify behaviour inconsistent with normal mail-service operation. 5️⃣ Review external-account and delivery-failure paths Do not hunt only authentication. If the deployment uses affected external POP3 or delivery-failure event handlers, correlate unusual remote-server responses with event-script activity and subsequent host behaviour. 🩹 Emergency remediation order: 1️⃣ Inventory the vulnerable condition Record version, OS, enabled event scripting, scripting language, affected handlers, service account and network exposure. 2️⃣ Upgrade to hMailServer 6.3.4+ The published remediation is to move beyond the affected 6.0.0–6.3.3 range. 3️⃣ Verify the running version Do not stop at “installer downloaded.” Confirm the actual service running after maintenance is the fixed build. 4️⃣ Disable unnecessary event scripting If event scripting is not operationally required, disabling the feature removes an unnecessary execution surface. Where scripts are required, review their language, handlers and allowed objects. 5️⃣ Review the historical exposure window If the server previously met the vulnerable configuration prerequisites while reachable from untrusted systems, inspect retained mail, application, Windows and network telemetry. 6️⃣ Escalate when evidence warrants it If suspicious server-side execution is identified, treat the machine as an incident rather than merely closing the vulnerability ticket. 🧱 Temporary exposure reduction. Where immediate upgrading is operationally delayed: ✅ disable event scripting when it is not required; ✅ avoid the vulnerable JScript configuration; ✅ restrict mail-service reachability where business requirements permit; ✅ minimise privileges of the hMailServer service account; ✅ review allowed script/COM capabilities; ✅ monitor hMailServer-originated child processes and unusual outbound connections. These are exposure-reduction measures. They are not a substitute for upgrading to the fixed release. 🚑 When vulnerability management becomes incident response. Escalate when you find: 🔴 unexplained process execution originating from hMailServer; 🔴 suspicious authentication/event activity immediately preceding host execution; 🔴 unexpected event-script modification; 🔴 unexplained outbound connections from the service context; 🔴 new persistence or executable content associated with the mail service; 🔴 evidence that credentials or connected services were accessed from the affected context. A vulnerable configuration alone does not prove compromise. Likewise, patching today does not prove that a historically exposed server was never abused. 📊 CISA KEV and EPSS context. At CyberForge review time on 28 September 2026: 🔹 CISA KEV: no listing found for CVE-2026-100741. 🔹 Active exploitation: no confirmed in-the-wild exploitation identified in the reviewed sources. 🔹 EPSS: current secondary trackers are inconsistent immediately after publication; one reports approximately 1.73% / 77th percentile, while another still reports no value. For a CVE this new, treat EPSS as supporting context, not the primary decision maker. The more useful first question is: Do I run an affected Windows version with the vulnerable JScript event configuration exposed to untrusted input? 🧾 Evidence separation: CVE / public-record confirmed 🔹 hMailServer 6.0.0–6.3.3 on Windows affected. 🔹 arbitrary JScript can execute in the hMailServer service context. 🔹 CVSS v3.1 9.8 Critical. 🔹 CWE-95 Eval Injection. 🔹 specific non-default JScript event configurations are required. 🔹 multiple mail/event paths can reach the vulnerable dispatcher. 🔹 Linux builds and VBScript event scripts are not affected. 🔹 version 6.3.4 is the fixed release. CyberForge interpretation 🔹 prioritise servers that actually meet the vulnerable configuration prerequisites; 🔹 correlate mail/event activity with Windows process telemetry; 🔹 inspect the full shared scripting boundary rather than only authentication; 🔹 assess real privilege and secret exposure from the service account before deciding incident scope. Not established ❌ active mass exploitation; ❌ a verified public campaign; ❌ automatic SYSTEM execution; ❌ persistence; ❌ credential theft; ❌ lateral movement; ❌ ransomware; ❌ data exfiltration. No exploit was executed during this CyberForge review. 🔥 CyberForge verdict: CVE-2026-100741 is a Critical pre-authentication eval-injection flaw where attacker-controlled mail-protocol data can cross an application boundary and become executable JScript inside an affected hMailServer service. The configuration prerequisites matter enormously: event scripting must be enabled, JScript selected, and an affected handler configured. But where those conditions exist, the consequence is serious — untrusted network data is no longer merely being parsed; it can become code. The correct order is: 1️⃣ Inventory affected Windows hMailServer instances and scripting configuration. 2️⃣ Upgrade vulnerable installations to 6.3.4 or later and verify the running version. 3️⃣ Disable unnecessary scripting and reduce service privileges/exposure. 4️⃣ Hunt mail/event activity against Windows host telemetry. 5️⃣ Scope secrets and connected systems according to actual service-account access. 6️⃣ Escalate to incident response where suspicious execution or configuration change is found. The CyberForge verdict: when protocol data is stitched directly into an interpreter, one broken escaping boundary can turn a mail event into a code-execution boundary. 🔗 Primary project / hMailServer: https://gitlab.com/Progressiverobot/hmailserver 🔗 CVE technical record / affected configuration and fix: https://www.tenable.com/cve/CVE-2026-100741 🔗 Additional vulnerability record: https://www.rapid7.com/db/vulnerabilities/cve-2026-100741/ 🔗 FIRST EPSS API: https://api.first.org/epss/ 🔗 CVE record: https://www.cve.org/CVERecord?id=CVE-2026-100741 🔗 NVD vulnerability record: https://nvd.nist.gov/vuln/detail/CVE-2026-100741 #CyberSecurity #CVE #hMailServer #Windows #RCE #EvalInjection #EmailSecurity #ThreatHunting #IncidentResponse #BlueTeam #SecOps #CyberForge

    0000025
    629 followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — HMAILSERVER CVE-2026-100741 CRITICAL UNAUNAUTHENTICATED REMOTE CODE EXECUTION September 27, 2026 — CVE-2026-100741 was published for a critical eval-injection vulnerability in hMailServer on Windows, rated CVSS 9.8. DISCLOSED BY: GitLab CVE / Progressive Robot Ltd PRODUCT: Progressive Robot Ltd hMailServer CVE: CVE-2026-100741 AFFECTED VERSIONS: hMailServer 6.0.0 through 6.3.3 on Windows IMPACT: An unauthenticated remote attacker can inject arbitrary JScript into the hMailServer service process under specific non-default event-scripting configurations. Successful exploitation executes code with the privileges of the hMailServer service account and may reach OS command execution through http://WScript.Shell where permitted by ScriptAllowedObjects. EXPOSURE CONDITIONS: Event scripting enabled — disabled by default Script language set to JScript — VBScript is the default A vulnerable handler such as OnClientValidatePassword is configured The attacker does not need the correct password, but the affected login path requires an existing active account name. Linux builds and VBScript event scripts are not affected according to the CVE record. EXPLOITATION STATUS: REMOTE UNAUTHENTICATED RCE CONFIRMED BY VULNERABILITY RECORD NO CONFIRMED IN-THE-WILD EXPLOITATION FOUND knownRansomwareCampaignUse: NOT ESTABLISHED Forensic triage: EXPOSURE CHECK FIRST — no official in-the-wild IoCs were identified in the primary sources checked. URGENT ACTION: Upgrade to hMailServer 6.3.4 or later. If immediate upgrading is not possible, disable event scripting where unnecessary or avoid JScript and the affected event handlers until patched. CONFIDENCE: HIGH — the CVE/GitHub Advisory documents the exploit path, affected configuration and impact, and the vendor has released hMailServer 6.3.4. SOURCE: https://github.com/advisories/GHSA-v6j4-p35g-mq6p VENDOR RELEASE: https://gitlab.com/Progressiverobot/hmailserver/-/releases/v6.3.4 FIX COMMIT: https://gitlab.com/Progressiverobot/hmailserver/-/commit/5a3de9001d6c5e833662ada8e44ce10d42d76b1a #CyberSecurity #ThreatIntel #hMailServer #CVE #RCE #EmailSecurity

    0000051
    226 followersView on X

Explore more