CVE-2026-35389
EUVD-2026-1947806.04.2026, 21:16
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email signed with a self-signed or untrusted certificate was displayed as having a valid signature. This vulnerability is fixed in 1.4.11.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bulwarkmail | webmail | 𝑥 < 1.4.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration