CVE-2026-107844
Received Received - Intake

Path Traversal in Contao CMS

Vulnerability report for CVE-2026-107844, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify that the canonical path remains inside that directory. An unauthenticated request containing encoded parent-directory segments can therefore return files under the project directory through BinaryFileResponse when their names use an extension allowed by contao.image.valid_extensions. The route can also reveal whether arbitrary paths exist, and debug responses can disclose absolute filesystem paths, but paths below the upload directory were not shown to be readable. This issue is fixed in versions 5.3.50 and 5.7.12.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
contao contao >= 5.0.0, < 5.3.50
contao contao >= 5.4.0-RC1, < 5.7.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107844 is a path traversal vulnerability in Contao CMS versions 5.0.0 to 5.3.50 and 5.7.12. It allows unauthenticated attackers to read files outside the intended directory by using percent-encoded parent-directory segments in the path parameter. The attack is limited to files with extensions defined in contao.image.valid_extensions like jpg, png, or svg.

Detection Guidance

Check Contao CMS version with: composer show contao/contao-core. If version is between 5.0.0 and 5.3.49 or 5.7.0 and 5.7.11, the system is vulnerable. Test for path traversal by sending encoded path requests like: curl -v 'http://target.com/_contao/images?path=..%2F..%2F..%2Fetc%2Fpasswd' and observe if files are returned.

Impact Analysis

This vulnerability could allow attackers to access sensitive files on your server if they are named with allowed extensions. It may also reveal whether arbitrary paths exist, acting as an existence oracle. However, it cannot access protected member folders or paths below the upload directory.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing sensitive files if attackers access them through path traversal. GDPR requires protecting personal data, while HIPAA mandates securing protected health information. Unauthorized file access may lead to data breaches, violating these regulations.

Mitigation Strategies

Upgrade Contao CMS to version 5.3.50 or 5.7.12 or later immediately. If immediate upgrade is not possible, restrict access to the /_contao/images route via web server configuration (e.g., Apache Deny or nginx deny rules) until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107844. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart