Executive brief
Bulwark Webmail is a self-hosted email client used to manage communications through Stalwart Mail Servers. A security flaw allows unauthorized individuals to bypass login requirements and modify user account settings. This could lead to unauthorized changes in user configurations or preferences, potentially compromising the integrity of the mail environment.
Technical details
An authentication bypass vulnerability exists in Bulwark Webmail's 'verifyIdentity()' function. The root cause is flawed logic that incorrectly returns 'true' (authenticated) if no session cookies are detected in the request. A remote, unauthenticated attacker can exploit this by sending requests with arbitrary headers to the '/api/settings' endpoint. This allows the attacker to view or modify user settings without a valid session. The issue is addressed in version 1.4.10 by removing the fallback logic that permitted access when cookies were missing.
Affected products
- Bulwark Webmail < 1.4.10
Timeline
- 2026-03-30: patched: Version 1.4.10 released
- 2026-03-31: advisory: Vendor advisory GHSA-4356-876g-rfmh published
- 2026-04-02: disclosed: CVE-2026-34834 published to NVD