OAuth Redirect URI Validation Flaw in Stalwart Mail Server by Stalwart Labs
CVE-2026-81036

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-81036?

The Stalwart Mail Server is vulnerable due to a lack of validation for the OAuth redirect target in its default settings. When the client-authentication requirement is disabled, the server does not match the redirect URI against any registered destinations. This opens the door for attackers to exploit the authorization code process, allowing them to redirect users to an attacker-controlled site. Once the user grants access, the attacker can capture the valid authorization code and exchange it for access and refresh tokens, potentially gaining unauthorized access to the victim's email and sensitive data.

Affected Version(s)

stalwart 0 <= 0.16.19

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.