๐Ÿ” CVE Alert

CVE-2026-107851

MEDIUM 4.3

Contao: Improper access control in the table access voter

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the user's security token, and omits the table returned by getDataSource(). If one request first checks a table allowed to the user and then a different denied table, the voter can reuse the allowed result, while DefaultDataContainerVoter can convert an incorrect abstention into a grant. A low-privileged backend user can consequently read, create, update, or delete records in tables outside assigned module permissions, including tables containing member or newsletter-subscriber data. This issue is fixed in version 5.7.12.

CWE CWE-524 CWE-863
Vendor contao
Product contao
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for contao contao

Be the first to know when new medium vulnerabilities affecting contao contao are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

contao / contao
>= 5.7.0, < 5.7.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/contao/contao/security/advisories/GHSA-5974-gfqc-wrcm github.com: https://github.com/contao/contao/commit/9d6f582a4cc6a758ce11d1043fc9c0ba62c5f4c9 github.com: https://github.com/contao/contao/releases/tag/5.7.12