CVE-2026-107842
Received Received - Intake

Information Disclosure in Contao CMS Search Module

Vulnerability report for CVE-2026-107842, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, ModuleSearch can disclose protected page titles, URLs, and indexed context snippets to unauthenticated visitors when contao.search.index_protected is changed from enabled to disabled. Authorization metadata is stored per row in tl_search, but disabling the setting removes the protected-row filter without deleting rows indexed while protection was enabled. The protected pages continue to return an authorization response, so this issue exposes search metadata and indexed text rather than bypassing page access. This issue is fixed in versions 5.3.50 and 5.7.12.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
contao contao >= 4.0.0, < 5.3.50
contao contao >= 5.4.0-RC1, < 5.7.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Contao CMS allows unauthenticated users to view protected page titles, URLs, and indexed text snippets through the search function when the setting contao.search.index_protected is disabled. The issue occurs because disabling the setting removes a filter that previously excluded protected pages from search results, but the indexed data from when protection was enabled remains accessible.

Detection Guidance

Check Contao CMS version with: composer show contao/core-bundle. If version is between 4.0.0 and 5.3.49 or 5.7.0 and 5.7.11, the system is vulnerable. Inspect ModuleSearch.php for missing protected page filtering logic.

Impact Analysis

This vulnerability exposes metadata about restricted content, such as titles and URLs of protected pages, to unauthorized users. While it does not bypass access controls, it reveals information that could be used to infer the existence of sensitive pages or content within the system.

Compliance Impact

This vulnerability may impact compliance with data protection regulations like GDPR or HIPAA by exposing metadata about restricted or sensitive content. Unauthorized disclosure of such information could violate privacy requirements or data protection policies.

Mitigation Strategies

Upgrade Contao CMS to version 5.3.50 or 5.7.12 or later. Ensure contao.search.index_protected remains enabled or clear and rebuild the search index after upgrade.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107842. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart