« Volver al listado

CVE-2026-34828

Estado: AnalizadaAlta (7.1)—

listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, a session management vulnerability allows previously issued authenticated sessions to remain valid after sensitive account security changes, specifically password reset and password change. As a result, an attacker who has already obtained a valid session cookie can retain access to the account even after the victim changes or resets their password. This weakens account recovery and session security guarantees. This issue has been patched in version 6.1.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Red con autenticación previa (PR:L) permite retener acceso post-cambio de contraseña; sesión válida = T1078.001. Confidencialidad alta (C:H) y integridad limitada (I:L).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-34828",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-34828",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-03T17:33:40.871656Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "knadh",
          "product": "listmonk",
          "versions": [
            {
              "status": "affected",
              "version": ">= 4.1.0, < 6.1.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-02T18:16:33.713",
  "references": [
    {
      "url": "https://github.com/knadh/listmonk/commit/db82035d619348949512dafdaf60c86037cafc9e",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/knadh/listmonk/releases/tag/v6.1.0",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/knadh/listmonk/security/advisories/GHSA-h5j9-cvrw-v5qh",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-613"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, a session management vulnerability allows previously issued authenticated sessions to remain valid after sensitive account security changes, specifically password reset and password change. As a result, an attacker who has already obtained a valid session cookie can retain access to the account even after the victim changes or resets their password. This weakens account recovery and session security guarantees. This issue has been patched in version 6.1.0."
    },
    {
      "lang": "es",
      "value": "listmonk es un gestor de boletines y listas de correo autónomo y autoalojado. Desde la versión 4.1.0 hasta antes de la versión 6.1.0, una vulnerabilidad de gestión de sesiones permite que las sesiones autenticadas emitidas previamente permanezcan válidas después de cambios de seguridad sensibles en la cuenta, específicamente el restablecimiento de contraseña y el cambio de contraseña. Como resultado, un atacante que ya ha obtenido una cookie de sesión válida puede retener el acceso a la cuenta incluso después de que la víctima cambie o restablezca su contraseña. Esto debilita las garantías de recuperación de cuenta y seguridad de la sesión. Este problema ha sido parcheado en la versión 6.1.0."
    }
  ],
  "lastModified": "2026-07-24T21:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nadh:listmonk:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB35DDE9-7F69-4344-A42C-C17C1F1D70A5",
              "versionEndExcluding": "6.1.0",
              "versionStartIncluding": "4.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}