Loading
Generated remediation guidance and an executive summary. No account required.
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email signed with a self-signed or untrusted certificate was displayed as having a valid signature. This vulnerability is fixed in 1.4.11.
Use CWE-295, Bulwarkmail vendor hub and Webmail product page to widen CVE-2026-35389 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-35391, CVE-2026-34834 and CVE-2026-34833 for nearby disclosures in the same product family.