Credential Leakage in Contao Open Source CMS
CVE-2026-55824
2.6LOW
What is CVE-2026-55824?
A security issue has been identified in Contao Open Source CMS, where the crawler potentially exposes authentication credentials to external hosts. Instances of Contao versions 4.13.40 through 5.3.46, and 5.7.0-RC1 through 5.7.6, improperly manage HTTP client options. Although the crawler attempts to sanitize these options, it fails to correctly handle certain authentication methods, allowing credentials to be leaked if an attacker can manage to get a specific URL crawled. This vulnerability has been addressed in the latest updates, which should be applied promptly to protect against unauthorized access.
Affected Version(s)
contao >= 4.13.40, < 5.3.47 < 4.13.40, 5.3.47
contao >= 5.7.0-RC1, < 5.7.7 < 5.7.0-RC1, 5.7.7
