Path Traversal Vulnerability in Contao CMS by Contao
CVE-2026-107844

5.3MEDIUM

Key Information:

Vendor

Contao

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107844?

A path traversal vulnerability exists in Contao CMS versions up to 5.3.50 and 5.7.12. The issue arises from the ImagesController's handling of the user-controlled {path} parameter, which is concatenated with the configured image target directory without sufficient validation. An attacker can manipulate the {path} parameter through encoded parent-directory segments, potentially revealing sensitive files within the project directory. This security flaw could also expose whether arbitrary filesystem paths exist and might inadvertently leak absolute filesystem paths through debug responses. Although this vulnerability does not allow access to paths located below the upload directory, it still poses a significant risk if left unaddressed. This issue is resolved in the latest releases: versions 5.3.50 and 5.7.12.

Affected Version(s)

contao >= 5.0.0, < 5.3.50 < 5.0.0, 5.3.50

contao >= 5.4.0-RC1, < 5.7.12 < 5.4.0-RC1, 5.7.12

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.