Bulwark Webmail Authentication Bypass Vulnerability in verifyIdentity() Function

Vulnerability

An authentication bypass vulnerability has been identified in Bulwark Webmail versions prior to 1.4.10. The issue arises in the verifyIdentity() function, which incorrectly returns true when no session cookies are present. This flaw allows unauthenticated attackers to bypass security checks and access or modify user settings through the /api/settings endpoint by sending arbitrary headers. The vulnerability has been patched in version 1.4.10, which removes the faulty logic and ensures that the function correctly returns false when no valid session is available.

Impact

Exploitation of this vulnerability allows for unauthorized access to user settings, which can be viewed or modified by the attacker.

Remediation

Users are strongly advised to upgrade to Bulwark Webmail version 1.4.10. Instructions for downloading the latest version are available on the Bulwark Webmail GitHub Releases page.

Added: Apr 2, 2026, 9:21 PM
Updated: Apr 2, 2026, 9:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
7.4
remediation
0.0
relevance
5.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.