CVE-2026-107843
Received Received - Intake

Email Flooding in Contao CMS via Unauthenticated Opt-In Token

Vulnerability report for CVE-2026-107843, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when reg_activate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
contao contao >= 4.1.0, < 5.3.50
contao contao >= 5.4.0-RC1, < 5.7.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
CWE-204 The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Contao CMS allows unauthenticated attackers to send unlimited activation emails to any address with a pending registration. The flaw occurs in the ModuleRegistration::compile() function, which triggers resendActivationMail() without verifying form submission or captcha results. This also acts as an account oracle, revealing if an address has a pending registration.

Detection Guidance

Check Contao CMS versions for affected releases (4.1.0 to 5.3.49 and 5.7.0 to 5.7.11). Monitor for excessive activation email requests to the same address. Review server logs for repeated POST requests to registration endpoints without form submission or captcha validation.

Impact Analysis

Attackers can spam email addresses with activation emails, causing nuisance and potential deliverability issues for the site. They can also determine if an email has a pending registration, compromising privacy. The attack requires no privileges or user interaction.

Compliance Impact

This vulnerability may violate GDPR by exposing personal data (email addresses) through the account oracle behavior. It could also lead to non-compliance with HIPAA if used to send unsolicited emails containing protected health information.

Mitigation Strategies

Upgrade Contao CMS to versions 5.3.50 or 5.7.12 or later. Implement rate limiting on registration endpoints. Disable reg_activate if not required. Monitor for suspicious activity in email logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107843. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart