{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/stalwart-mail-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-81036"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Stalwart Mail Server"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Stalwart Labs"],"content_html":"\u003cp\u003eStalwart Mail Server contains a vulnerability (CVE-2026-81036) in its OAuth implementation where redirect URI targets are not properly validated against registered destinations. The flaw originates in the validation routine located at crates/http/src/auth/oauth/registration.rs. Due to the shipped default configuration having client-authentication requirements disabled, the validation routine returns immediate success for any provided redirect URI.\u003c/p\u003e\n\u003cp\u003eThe application stores the attacker-supplied redirect value alongside the authorization code. During the authentication process, the application redirects the user's browser to this attacker-controlled destination with the authorization code attached. Because the token exchange endpoint only verifies that the redirect URI presented during the exchange matches the one recorded with the code, the attacker can successfully exchange the code for valid access and refresh tokens, leading to full unauthorized access to the victim's mail account.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious request containing a custom 'redirect_uri' parameter pointing to an attacker-controlled endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker induces a victim to initiate an OAuth authentication flow through the vulnerable Stalwart Mail Server.\u003c/li\u003e\n\u003cli\u003eThe server processes the OAuth request, fails to validate the redirect URI due to the insecure default configuration, and stores the malicious URI.\u003c/li\u003e\n\u003cli\u003eThe victim authenticates successfully via the legitimate OAuth provider.\u003c/li\u003e\n\u003cli\u003eThe server sends an HTTP 302 redirect, instructing the victim's browser to send the authorization code to the attacker's server.\u003c/li\u003e\n\u003cli\u003eAttacker captures the authorization code from the incoming request logs.\u003c/li\u003e\n\u003cli\u003eAttacker presents the captured authorization code and the original malicious redirect URI to the Stalwart token endpoint.\u003c/li\u003e\n\u003cli\u003eThe server issues valid access and refresh tokens to the attacker, providing unauthorized access to the victim's account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized actors to intercept authorization codes and exchange them for permanent access and refresh tokens. This results in complete compromise of the victim's email account, enabling exfiltration of sensitive data and continued unauthorized access to the mail service.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eReview Stalwart Mail Server configuration files to verify the status of client-authentication requirements.\u003c/li\u003e\n\u003cli\u003ePatch the server to the latest version that enforces strict redirect URI validation regardless of authentication settings.\u003c/li\u003e\n\u003cli\u003eAudit application access logs for unexpected redirect URIs associated with OAuth authentication attempts.\u003c/li\u003e\n\u003cli\u003eImplement strict allowlisting for OAuth redirect URIs if the environment permits, ensuring only trusted destinations are permitted.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-26T16:22:40Z","date_published":"2026-08-26T16:22:40Z","id":"https://feed.craftedsignal.io/briefs/2026-08-stalwart-oauth-redirect/","summary":"Stalwart Mail Server suffers from an OAuth open redirect vulnerability in its default configuration that allows attackers to hijack authorization codes and gain unauthorized access to user accounts.","title":"CVE-2026-81036: OAuth Redirect Validation Bypass in Stalwart Mail Server","url":"https://feed.craftedsignal.io/briefs/2026-08-stalwart-oauth-redirect/"}],"language":"en","title":"CraftedSignal Threat Feed - Stalwart Mail Server","version":"https://jsonfeed.org/version/1.1"}