Generated remediation guidance and an executive summary. No account required.
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that returned true if no session cookies were present. This allowed unauthenticated attackers to bypass security checks and access/modify user settings via the /api/settings endpoint by providing arbitrary headers. This issue has been patched in version 1.4.10.
Cite this page
CVE-2026-34834. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-34834
Use CWE-287, Bulwarkmail vendor hub and Webmail product page to widen CVE-2026-34834 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-35391, CVE-2026-35389 and CVE-2026-34833 for nearby disclosures in the same product family.