PT-2026-30727 · Unknown · Stalwart Mail Server+1

·

CVE-2026-35389

·

Published

2026-04-06

·

Updated

2026-04-06

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Bulwark Webmail versions prior to 1.4.11
Description Bulwark Webmail, a self-hosted webmail client for Stalwart Mail Server, had an issue in S/MIME signature verification. Before version 1.4.11, the software did not validate the certificate trust chain during signature verification. This meant that emails signed with self-signed or untrusted certificates were incorrectly displayed as having valid signatures.
Recommendations Update to version 1.4.11 or later.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35389
GHSA-V6W6-338P-P256

Affected Products

Bulwark Webmail
Stalwart Mail Server