๐Ÿ” CVE Alert

CVE-2026-34584

MEDIUM 5.4

listmonk: Broken Access Control in CSV Import (Unauthorized List Assignment)

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission checks allows users in a multi-user environment to access to lists (which they don't have access to) under different scenarios. This only affects multi-user environments with untrusted users. This issue has been patched in version 6.1.0.

CWE CWE-639
Vendor knadh
Product listmonk
Published Apr 2, 2026
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for knadh listmonk

Be the first to know when new medium vulnerabilities affecting knadh listmonk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

knadh / listmonk
>= 4.1.0, < 6.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/knadh/listmonk/security/advisories/GHSA-85j8-5c6w-gcpv github.com: https://github.com/knadh/listmonk/commit/347f5976759232c36e571cf58b4bfe33c2794f35 github.com: https://github.com/knadh/listmonk/releases/tag/v6.1.0