A vulnerability classified as critical has been found in bulwarkmail webmail up to 1.4.10. The affected element is an unknown function of the component SMIME Signature Verification. This manipulation causes improper certificate validation.

The identification of this vulnerability is CVE-2026-35389. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.