


Perceptive Security
SOC/SIEM Consultancy

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates…
Published:
26 August 2026 at 00:00:00
Alert date:
26 August 2026 at 19:06:19
Source:
nvd.nist.gov
Email & Messaging, Identity & Access, Web Technologies
Stalwart Mail Server contains a critical OAuth vulnerability where redirect URIs are not validated against registered destinations in the default configuration. The validation routine in the OAuth registration code returns success immediately when client-authentication is disabled, which is the default shipped setting. This allows an attacker to supply an arbitrary redirect URI, which gets stored with the authorization code. When a legitimate user authenticates, the authorization code is sent to the attacker-controlled destination. The attacker can then exchange the code for access and refresh tokens since the token endpoint only verifies that the redirect URI matches what was recorded with the code. This effectively allows full account takeover and unauthorized access to the victim's email. The flaw affects Stalwart Mail Server through version 0.16.19.
Technical details
Mitigation steps:
Affected products:
Stalwart Mail Server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-81036
https://github.com/stalwartlabs/stalwart
https://github.com/stalwartlabs/stalwart/blob/v0.16.19/crates/http/src/auth/oauth/registration.rs
https://github.com/stalwartlabs/stalwart/issues/3205
https://www.vulncheck.com/advisories/stalwart-mail-server-through-0.16.19-authorization-code-disclosure-via-unvalidated-oauth-redirect-uri
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
