PT-2026-82224 · Unknown · Stalwart Mail Server
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Stalwart Mail Server (affected versions not specified)
Description
In its default configuration, the server fails to validate OAuth redirect targets against registered destinations. The validation routine in
crates/http/src/auth/oauth/registration.rs returns success immediately when client-authentication is disabled, which is the default setting. This allows an attacker to specify a destination they control; once the account holder authenticates, a valid authorization code is sent to that destination. The attacker can then exchange this code at the token endpoint for access and refresh tokens to read the account mail.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stalwart Mail Server