CVE-2026-107848
Received Received - Intake

CSRF Bypass in Contao CMS

Vulnerability report for CVE-2026-107848, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
contao contao >= 4.0.0, < 5.3.50
contao contao >= 5.4.0-RC1, < 5.7.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Contao CMS versions 4.0.0 to 5.3.50 and 5.7.12 have a vulnerability where RequestTokenListener only validates CSRF tokens for POST requests. GET requests with an act parameter bypass this check, allowing backend actions to execute without a valid token when an authenticated user visits a malicious URL. This could lead to unauthorized state changes or destructive actions within the user's permissions.

Impact Analysis

If you use a vulnerable Contao CMS version, an attacker could trick you into clicking a link that performs unwanted backend actions, such as deleting content or modifying settings, without your knowledge. The impact is limited to actions your user account is permitted to perform.

Compliance Impact

This vulnerability could lead to unauthorized modifications of data, potentially violating integrity requirements in GDPR or HIPAA. If exploited, it may result in non-compliance due to unauthorized changes to sensitive information or system configurations.

Mitigation Strategies

Upgrade Contao to versions 5.3.50 or 5.7.12 or later to fix the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107848. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart