Open Source CMS Contao Vulnerability in ModuleSearch Settings
CVE-2026-107842
5.3MEDIUM
What is CVE-2026-107842?
A vulnerability exists in Contao CMS where the ModuleSearch functionality can inadvertently expose protected page titles, URLs, and indexed snippets to unauthenticated users. This issue arises when the setting 'contao.search.index_protected' is disabled, allowing previously protected search metadata to be accessible, although page access remains restricted. The problem lies in the treatment of authorization metadata, which isn't adequately removed, resulting in unauthorized data visibility. Versions 5.3.50 and 5.7.12 resolve this vulnerability.
Affected Version(s)
contao >= 4.0.0, < 5.3.50 < 4.0.0, 5.3.50
contao >= 5.4.0-RC1, < 5.7.12 < 5.4.0-RC1, 5.7.12
