Executive brief
HSC MailInspector, an enterprise email security gateway used to protect organizations from phishing and malware, is vulnerable to a security flaw that allows unauthorized access to system files. By sending a specially crafted web request, an attacker can bypass directory restrictions to read sensitive configuration files or system data. This could lead to the exposure of credentials, internal system details, and other confidential information stored on the appliance.
Technical details
A Path Traversal vulnerability exists in HSC MailInspector v5.3.3-7 within the /tap/dw.php endpoint. The application fails to properly validate or normalize user-supplied input provided via the 'ext' (or 'text' as cited in some descriptions) parameter before using it to construct file paths. A remote, unauthenticated attacker can exploit this by using directory traversal sequences (e.g., ../../) to escape the intended base directory and access sensitive files on the underlying operating system. This is classified as CWE-22 and can result in Local File Inclusion (LFI) and unauthorized disclosure of system configuration or application data.
Affected products
- HSC MailInspector 5.3.3-7
Timeline
- 2026-05-18: disclosed: Initial vulnerability disclosure and CVE assignment
- 2026-05-18: advisory: NVD publication date