Junglewise Threat Intelligence

CVE-2026-29962: HSC MailInspector Local File Inclusion in phpunit.php

CVE-2026-29962 · Severity: info · CVSS 7.5 · Published 2026-05-18

Technologies: HSC MailInspector. Vendors: HSC.

Executive brief

HSC MailInspector, an email security gateway used to protect organizations from phishing and malware, contains a vulnerability that allows unauthorized access to system files. By sending a specially crafted request to a specific component, an attacker can bypass security restrictions to read sensitive configuration files, credentials, or application data. This could lead to the exposure of administrative secrets or provide a foothold for further attacks on the corporate network.

Technical details

A Local File Inclusion (LFI) and Path Traversal vulnerability exists in HSC MailInspector v5.3.3-7. The vulnerability is located in the '/vendor/phpunit/phpunit.php' endpoint, which fails to properly validate, sanitize, or restrict user-supplied file paths in its parameters. A remote, unauthenticated attacker can exploit this by using '../' sequences to traverse the file system and read sensitive files from the underlying operating system or application directories. This can result in the disclosure of API keys, database credentials, and internal architectural details. The issue is tracked as CWE-73 (External Control of File Name or Path).

Affected products

  • HSC MailInspector 5.3.3-7

Timeline

  • 2026-05-18: advisory: CVE-2026-29962 published by NVD/MITRE

References

Related threats