CVE-2026-34828

Source
https://cve.org/CVERecord?id=CVE-2026-34828
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34828.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-34828
Aliases
Downstream
Related
Published
2026-04-02T17:32:24.756Z
Modified
2026-07-31T18:31:06.130789887Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
listmonk: Active sessions remain valid after password reset and password change
Details

listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, a session management vulnerability allows previously issued authenticated sessions to remain valid after sensitive account security changes, specifically password reset and password change. As a result, an attacker who has already obtained a valid session cookie can retain access to the account even after the victim changes or resets their password. This weakens account recovery and session security guarantees. This issue has been patched in version 6.1.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-613"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34828.json"
}
References

Affected packages

Git / github.com/knadh/listmonk

Affected ranges

Type
GIT
Repo
https://github.com/knadh/listmonk
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:nadh:listmonk:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.1.0"
        },
        {
            "fixed": "6.1.0"
        }
    ]
}

Affected versions

Other
nightly
v4.*
v4.1.0
v5.*
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.1.0
v6.*
v6.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34828.json"