High severity7.5NVD Advisory· Published Apr 6, 2026· Updated Apr 9, 2026
CVE-2026-35389
CVE-2026-35389
Description
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email signed with a self-signed or untrusted certificate was displayed as having a valid signature. This vulnerability is fixed in 1.4.11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- github.com/bulwarkmail/webmail/security/advisories/GHSA-v6w6-338p-p256nvdVendor Advisory
News mentions
0No linked articles in our index yet.