top of page
perceptive_background_267k.jpg

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates…

Published:

26 August 2026 at 00:00:00

Alert date:

26 August 2026 at 19:06:19

Source:

nvd.nist.gov

Click to open the original link from this advisory

Email & Messaging, Identity & Access, Web Technologies

Stalwart Mail Server contains a critical OAuth vulnerability where redirect URIs are not validated against registered destinations in the default configuration. The validation routine in the OAuth registration code returns success immediately when client-authentication is disabled, which is the default shipped setting. This allows an attacker to supply an arbitrary redirect URI, which gets stored with the authorization code. When a legitimate user authenticates, the authorization code is sent to the attacker-controlled destination. The attacker can then exchange the code for access and refresh tokens since the token endpoint only verifies that the redirect URI matches what was recorded with the code. This effectively allows full account takeover and unauthorized access to the victim's email. The flaw affects Stalwart Mail Server through version 0.16.19.

Technical details

Mitigation steps:

Affected products:

Stalwart Mail Server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page