CVE-2026-34584

listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission checks allows users in a multi-user environment to access to lists (which they don't have access to) under different scenarios. This only affects multi-user environments with untrusted users. This issue has been patched in version 6.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nadh:listmonk:*:*:*:*:*:*:*:*

History

10 Apr 2026, 02:03

Type Values Removed Values Added
CPE cpe:2.3:a:nadh:listmonk:*:*:*:*:*:*:*:*
First Time Nadh
Nadh listmonk
References () https://github.com/knadh/listmonk/commit/347f5976759232c36e571cf58b4bfe33c2794f35 - () https://github.com/knadh/listmonk/commit/347f5976759232c36e571cf58b4bfe33c2794f35 - Patch
References () https://github.com/knadh/listmonk/releases/tag/v6.1.0 - () https://github.com/knadh/listmonk/releases/tag/v6.1.0 - Product, Release Notes
References () https://github.com/knadh/listmonk/security/advisories/GHSA-85j8-5c6w-gcpv - () https://github.com/knadh/listmonk/security/advisories/GHSA-85j8-5c6w-gcpv - Patch, Vendor Advisory

02 Apr 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 18:16

Updated : 2026-04-10 02:03


NVD link : CVE-2026-34584

Mitre link : CVE-2026-34584

CVE.ORG link : CVE-2026-34584


JSON object : View

Products Affected

nadh

  • listmonk
CWE
CWE-639

Authorization Bypass Through User-Controlled Key