PT-2026-82224 · Unknown · Stalwart Mail Server

·

CVE-2026-81036

·

Published

2026-08-26

·

Updated

2026-08-29

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Stalwart Mail Server (affected versions not specified)
Description In its default configuration, the server fails to validate OAuth redirect targets against registered destinations. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when client-authentication is disabled, which is the default setting. This allows an attacker to specify a destination they control; once the account holder authenticates, a valid authorization code is sent to that destination. The attacker can then exchange this code at the token endpoint for access and refresh tokens to read the account mail.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81036

Affected Products

Stalwart Mail Server