THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-81036 (HIGH 8.1) — Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled,

[NVD] CVE-2026-81036 (HIGH 8.1) — Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled,

mednvdPublished 2026-08-26

CVE-2026-81036 CVSS: 8.1 HIGH Published: 2026-08-26T16:16:46.607

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled, and that requirement is false in the shipped settings

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81036