← back
CVE-2026-34828

listmonk: Active sessions remain valid after password reset and password change

CVSS 7.1 HIGHEPSS 0.3%CWE-613
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.1EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
02 Apr 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, a session management vulnerability allows previously issued authenticated sessions to remain valid after sensitive account security changes, specifically password reset and password change. As a result, an attacker who has already obtained a valid session cookie can retain access to the account even after the victim changes or resets their password. This weakens account recovery and session security guarantees. This issue has been patched in version 6.1.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Affected products
knadh · listmonk

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →