PatchSiren cyber security CVE debrief
CVE-2026-107851 contao CVE debrief
A low-privileged backend user in Contao, an Open Source CMS, can read, create, update, or delete records in tables outside assigned module permissions due to improper access control in the table access voter. This issue is fixed in version 5.7.12. The vulnerability allows unauthorized data access, and defenders should prioritize patching to prevent exploitation. The issue arises from the TableAccessVoter::hasAccessToModule() function caching authorization decisions using only $tokenHash, omitting the table returned by getDataSource().
- Vendor
- contao
- Product
- Unknown
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Defenders and administrators of Contao installations should assess exposure and prioritize patching to prevent unauthorized data access. They should review module permissions for low-privileged backend users and monitor for unauthorized access to sensitive tables. Security teams should verify and apply the patch to Contao version 5.7.12 and review compensating controls for exposed systems.
Why it matters
Defenders should care about CVE-2026-107851 as it allows low-privileged backend users to access sensitive data outside their module permissions in Contao. The issue requires verification of exposure and prompt patching to prevent unauthorized data access.
- Potential unauthorized data access
- Elevation of privileges for low-privileged users
- Data tampering or deletion possible
Technical summary
The TableAccessVoter::hasAccessToModule() function in Contao caches authorization decisions using only $tokenHash, omitting the table returned by getDataSource(). This allows a low-privileged backend user to read, create, update, or delete records in tables outside assigned module permissions. The issue requires verification of exposure and prompt patching to prevent unauthorized data access. The vulnerability is fixed in Contao version 5.7.12, and defenders should prioritize applying the patch to prevent exploitation.
Defensive priority
Defenders should prioritize verifying and applying the patch to prevent unauthorized data access.
Recommended defensive actions
- Verify and apply the patch to Contao version 5.7.12
- Review and update module permissions for low-privileged backend users
- Monitor for unauthorized access to sensitive tables
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability and its fix. The issue is confirmed in Contao versions 5.7.0 through 5.7.11. Defenders should verify exposure and apply the patch to prevent unauthorized data access. Evidence is based on the CVE Program record and source item details, with limitations on affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107851 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107851
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107851 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107851
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Contao: Improper access control in the table access voter
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107851.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/contao/contao/security/advisories/GHSA-5974-gfqc-wrcm
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/contao/contao/commit/9d6f582a4cc6a758ce11d1043fc9c0ba62c5f4c9
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/contao/contao/releases/tag/5.7.12
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.