CVE-2026-104660 | Progressive Robot hMailServer up to 6.3.5 COM Objects path/AccountID improper authorization
A vulnerability categorized as critical has been discovered in Progressive Robot hMailServer up to 6.3.5. This affects the function Attachments.Add/Attachment.SaveAs/Message.Save/Message.Copy/FetchAccount.Save of the component COM Objects. Executing a manipulation of the argument path/AccountID can lead to improper authorization.
This vulnerability appears as CVE-2026-104660. The attack requires local access. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More