5.4
CVE-2026-34584
- EPSS 0.17%
- Veröffentlicht 02.04.2026 17:31:37
- Zuletzt bearbeitet 10.04.2026 02:03:22
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
listmonk: Broken Access Control in CSV Import (Unauthorized List Assignment)
listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission checks allows users in a multi-user environment to access to lists (which they don't have access to) under different scenarios. This only affects multi-user environments with untrusted users. This issue has been patched in version 6.1.0.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.067 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://github.com/knadh/listmonk/security/advisories/GHSA-85j8-5c6w-gcpv
https://github.com/knadh/listmonk/commit/347f5976759232c36e571cf58b4bfe33c2794f35
https://github.com/knadh/listmonk/releases/tag/v6.1.0