The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-104658 is a privilege escalation vulnerability in hMailServer's live-update helper (hmailserver-update) that runs with root privileges while trusting untrusted input from an unprivileged service account. The vulnerability allows an attacker who has already achieved code execution as the hmailserver service account to escalate privileges to root by manipulating request files that specify which verification program to use and which systemd units to stop. This affects hMailServer versions 6.3.4 and 6.3.5, and is particularly dangerous because it converts a lower-privilege compromise into full system compromise. Organizations running vulnerable versions of hMailServer are exposed to complete system takeover through a two-stage attack: initial compromise of the mail service, followed by privilege escalation to root access.
While this CVE does not map to specific MITRE ATT&CK techniques in public databases, it represents exploitation of CWE-807 (Reliance on Untrusted Inputs in a Security Decision). Casky's AI-driven analysis with extended reasoning would detect attack patterns associated with Privilege Escalation (T1134) and Exploitation for Privilege Escalation (T1548), identifying suspicious systemd unit manipulation and unexpected verification binary execution originating from the hmailserver service account. Practitioners using Casky would observe findings highlighting: (1) service account processes spawning root-level operations through the hmailserver-update binary, (2) file system writes to update request directories by unprivileged accounts preceding privilege escalation, and (3) unusual verification tool invocations from non-standard paths. The platform's mapping of 754 security skills would correlate these indicators with known escalation patterns, enabling detection of the attack chain even in environments where initial mail service compromise indicators may have been missed.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-104658. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation