๐Ÿ” CVE Alert

CVE-2026-107850

MEDIUM 4.3

Contao: Improper access control in the preview links module

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Contao is an Open Source CMS. From version 5.7.1 until 5.7.12, core-bundle/config/services.yaml registers the preview access voter as Contao\CoreBundle\Security\Voter\DataContainer\PreviewAccessVoter although the shipped class is PreviewVoter. Symfony therefore omits voter autoconfiguration and removes the private service, so PreviewVoter::hasAccess() never enforces ownership. A non-admin backend user with the preview_link module can list every tl_preview_link record, obtain signed share URLs created by other users, and use them to view unpublished pages with showUnpublished despite lacking page permission. The advisory does not establish editing or deletion of foreign links. This issue is fixed in version 5.7.12.

CWE CWE-639 CWE-862
Vendor contao
Product contao
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for contao contao

Be the first to know when new medium vulnerabilities affecting contao contao are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

contao / contao
>= 5.7.1, < 5.7.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/contao/contao/security/advisories/GHSA-q6wp-fr43-gm9v github.com: https://github.com/contao/contao/commit/6b483d380a4b2dc61432c4c697e411508f93bf91 github.com: https://github.com/contao/contao/releases/tag/5.7.12