CVE-2026-107851
Received Received - Intake

Authorization Bypass in Contao CMS

Vulnerability report for CVE-2026-107851, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the user's security token, and omits the table returned by getDataSource(). If one request first checks a table allowed to the user and then a different denied table, the voter can reuse the allowed result, while DefaultDataContainerVoter can convert an incorrect abstention into a grant. A low-privileged backend user can consequently read, create, update, or delete records in tables outside assigned module permissions, including tables containing member or newsletter-subscriber data. This issue is fixed in version 5.7.12.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
contao contao >= 5.7.0, < 5.7.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-524 The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Contao CMS versions 5.7.0 to 5.7.12. It involves a security flaw in TableAccessVoter::hasAccessToModule() where authorization decisions are cached using only the user's security token hash, ignoring the specific table being accessed. This allows incorrect permission checks, potentially granting unauthorized access to sensitive data like member or newsletter-subscriber records.

Impact Analysis

A low-privileged backend user could exploit this to read, create, update, or delete records in tables they should not have access to. This includes accessing sensitive data such as member information or newsletter subscribers, leading to potential data breaches or unauthorized modifications.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of personal data, violating GDPR's data protection principles and HIPAA's security requirements. Organizations using affected Contao versions may face compliance violations, legal penalties, and reputational damage due to potential data breaches.

Mitigation Strategies

Update Contao to version 5.7.12 or later to fix the vulnerability. Review backend user permissions to ensure they align with module access requirements.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107851. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart