Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 10 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nadh:listmonk:*:*:*:*:*:*:*:* |
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nadh
Nadh listmonk |
|
| Vendors & Products |
Nadh
Nadh listmonk |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission checks allows users in a multi-user environment to access to lists (which they don't have access to) under different scenarios. This only affects multi-user environments with untrusted users. This issue has been patched in version 6.1.0. | |
| Title | listmonk: Broken Access Control in CSV Import (Unauthorized List Assignment) | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-02T19:09:02.060Z
Reserved: 2026-03-30T16:56:30.999Z
Link: CVE-2026-34584
Updated: 2026-04-02T19:08:57.370Z
Status : Analyzed
Published: 2026-04-02T18:16:30.510
Modified: 2026-04-10T02:03:22.047
Link: CVE-2026-34584
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:45:44Z