Back to CVE List

CVE-2026-34833

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Description

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to browser logs, local caches, and network proxie. This issue has been patched in version 1.4.10.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-312
Source
NVD
Vendor
bulwarkmail
Product
webmail

External References

Discussion (0)

Add Comment

No comments yet. Be the first!