Loading
Generated remediation guidance and an executive summary. No account required.
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to browser logs, local caches, and network proxie. This issue has been patched in version 1.4.10.
Use CWE-312, Bulwarkmail vendor hub and Webmail product page to widen CVE-2026-34833 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-35391, CVE-2026-35389 and CVE-2026-34834 for nearby disclosures in the same product family.