Untriaged
Permalink
CVE-2026-34584
5.4 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
listmonk: Broken Access Control in CSV Import (Unauthorized List Assignment)
listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission checks allows users in a multi-user environment to access to lists (which they don't have access to) under different scenarios. This only affects multi-user environments with untrusted users. This issue has been patched in version 6.1.0.
References
-
https://github.com/knadh/listmonk/security/advisories/GHSA-85j8-5c6w-gcpv x_refsource_CONFIRM
-
https://github.com/knadh/listmonk/releases/tag/v6.1.0 x_refsource_MISC
Affected products
listmonk
- ==>= 4.1.0, < 6.1.0
Package maintainers
-
@RaitoBezarius Ryan Lahfa <ryan@lahfa.xyz>