CVE-2026-107850
Received Received - Intake

Preview Access Bypass in Contao CMS

Vulnerability report for CVE-2026-107850, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Contao is an Open Source CMS. From version 5.7.1 until 5.7.12, core-bundle/config/services.yaml registers the preview access voter as Contao\CoreBundle\Security\Voter\DataContainer\PreviewAccessVoter although the shipped class is PreviewVoter. Symfony therefore omits voter autoconfiguration and removes the private service, so PreviewVoter::hasAccess() never enforces ownership. A non-admin backend user with the preview_link module can list every tl_preview_link record, obtain signed share URLs created by other users, and use them to view unpublished pages with showUnpublished despite lacking page permission. The advisory does not establish editing or deletion of foreign links. This issue is fixed in version 5.7.12.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
contao contao >= 5.7.1, < 5.7.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Contao CMS versions 5.7.1 to 5.7.12. A misconfiguration in services.yaml registers PreviewAccessVoter instead of PreviewVoter. This causes Symfony to disable voter autoconfiguration and remove the PreviewVoter service. As a result, the PreviewVoter::hasAccess() method does not enforce ownership checks. Non-admin users with the preview_link module can list all preview links, obtain signed URLs created by others, and view unpublished pages they should not access.

Detection Guidance

This vulnerability is specific to Contao CMS versions 5.7.1 to 5.7.12. Check your Contao version by inspecting the composer.json file or running composer show contao/core-bundle. If the version is within the affected range, the system is vulnerable.

Impact Analysis

If you use Contao CMS versions 5.7.1 to 5.7.12, a non-admin user with preview_link access could view unpublished pages belonging to other users. This could expose sensitive or confidential content before its intended publication. The attacker cannot edit or delete these links, only view pages through shared URLs.

Compliance Impact

This vulnerability could lead to unauthorized access to unpublished content, potentially violating data confidentiality requirements in GDPR and HIPAA. Exposure of sensitive data before official release may result in compliance violations, regulatory penalties, and loss of trust.

Mitigation Strategies

Upgrade Contao CMS to version 5.7.12 or later immediately. This can be done via Composer by running composer update contao/core-bundle. After updating, clear the cache with php bin/console cache:clear.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107850. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart