Credential Leakage in Contao Open Source CMS
CVE-2026-55824

2.6LOW

Key Information:

Vendor

Contao

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-55824?

A security issue has been identified in Contao Open Source CMS, where the crawler potentially exposes authentication credentials to external hosts. Instances of Contao versions 4.13.40 through 5.3.46, and 5.7.0-RC1 through 5.7.6, improperly manage HTTP client options. Although the crawler attempts to sanitize these options, it fails to correctly handle certain authentication methods, allowing credentials to be leaked if an attacker can manage to get a specific URL crawled. This vulnerability has been addressed in the latest updates, which should be applied promptly to protect against unauthorized access.

Affected Version(s)

contao >= 4.13.40, < 5.3.47 < 4.13.40, 5.3.47

contao >= 5.7.0-RC1, < 5.7.7 < 5.7.0-RC1, 5.7.7

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.