CVE-2026-35391
Last modified
CVE-2026-35391 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of the X-Forwarded-For header, which is fully controlled by the client. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of the X-Forwarded-For header, which is fully controlled by the client. An attacker could forge their source IP address to bypass IP-based rate limiting (enabling brute-force attacks against the admin login) or forge audit log entries (making malicious activity appear to originate from arbitrary IP addresses). This vulnerability is fixed in 1.4.11.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bulwarkmail | Webmail | < 1.4.11 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-35391?
How severe is CVE-2026-35391?
How do I fix CVE-2026-35391?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-35386In OpenSSH before 10.3, command execution can occur via shel…8.1
- CVE-2026-35387OpenSSH before 10.3 can use unintended ECDSA algorithms. Lis…6.5
- CVE-2026-35388OpenSSH before 10.3 omits connection multiplexing confirmati…2.5
- CVE-2026-35389Bulwark Webmail is a self-hosted webmail client for Stalwart…7.5
- CVE-2026-3539Rejected reason: Determined a bug and not a vulnerability
- CVE-2026-35390Bulwark Webmail is a self-hosted webmail client for Stalwart…5.4
- CVE-2026-35392goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-be…9.8
- CVE-2026-35393goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-be…9.8
- CVE-2026-35394Mobile Next is an MCP server for mobile development and auto…8.8
- CVE-2026-35395WeGIA is a Web manager for charitable institutions. Prior to…8.8
- CVE-2026-35396WeGIA is a Web manager for charitable institutions. Prior to…6.1
- CVE-2026-35397Jupyter Server is the backend for Jupyter web applications. …8.8
Are you affected by CVE-2026-35391?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
