Authorization Flaw in Contao Open Source CMS Affects User Permissions
CVE-2026-107851

4.3MEDIUM

Key Information:

Vendor

Contao

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107851?

The Contao Open Source CMS suffers from a vulnerability in the TableAccessVoter component, where unauthorized access decisions are cached improperly. This flaw arises in versions 5.7.0 to 5.7.12 due to the mishandling of security tokens, allowing low-privileged backend users to exploit the system and gain access to restricted data across various tables. Exploiters may read, create, update, or delete sensitive information, impacting user privacy and data integrity. This issue is addressed in version 5.7.12.

Affected Version(s)

contao >= 5.7.0, < 5.7.12

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.