CVE-2026-34828 describes a high-severity session management vulnerability in listmonk versions 4.1.0 through 6.0.x, where authenticated sessions persist even after a user changes or resets their password. This flaw allows an attacker with a previously obtained session cookie to retain unauthorized access, posing a significant risk to account confidentiality. Rated CVSS 7.1, it has a network attack vector and low attack complexity, requiring low privileges (an existing session) to exploit. The vulnerability weakens account recovery and session security guarantees. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.1.0, < 6.1.0CPE matchmatch criteria | cpe:2.3:a:nadh:listmonk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.