Authentication Vulnerability in Bulwark Webmail by Stalwart
CVE-2026-34833
8.7HIGH
What is CVE-2026-34833?
The Bulwark Webmail client, used with the Stalwart Mail Server, has a significant flaw where user credentials were exposed through the API. Specifically, prior to version 1.4.10, the GET /api/auth/session endpoint returned plaintext passwords in its JSON responses. This serious issue allowed malicious actors to access sensitive information through browser logs, local caches, and network proxies. Users are strongly encouraged to upgrade to the patched version 1.4.10 to mitigate this vulnerability.
Affected Version(s)
webmail < 1.4.10
