CVE-2026-34584

listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission checks allows users in a multi-user environment to access to lists (which they don't have access to) under different scenarios. This only affects multi-user environments with untrusted users. This issue has been patched in version 6.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nadh:listmonk:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-02 18:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-34584

Mitre link : CVE-2026-34584

CVE.ORG link : CVE-2026-34584


JSON object : View

Products Affected

nadh

  • listmonk
CWE
CWE-639

Authorization Bypass Through User-Controlled Key