CVE-2026-35389 Details
Description
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email signed with a self-signed or untrusted certificate was displayed as having a valid signature. This vulnerability is fixed in 1.4.11.
A vulnerability exists in Bulwark Webmail, a self-hosted webmail client for Stalwart Mail Server, in versions prior to 1.4.11. The issue arises because S/MIME signature verification did not properly validate the certificate trust chain, allowing emails signed with self-signed or untrusted certificates to be incorrectly displayed as having valid signatures. This vulnerability is particularly concerning for users who relied on the S/MIME signature verification feature.
Users are advised to upgrade to Bulwark Webmail version 1.4.11 or later, where this vulnerability has been fixed by enabling proper certificate chain validation. There are no workarounds available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bulwarkmail/webmail/security/advisories/GHSA-v6w6-338p-p256 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bulwarkmail webmail | < 1.4.11 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 9, 2026 | Initial Analysis | [email protected] |
| Apr 6, 2026 | New CVE Received | [email protected] |