PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107851 contao CVE debrief

A low-privileged backend user in Contao, an Open Source CMS, can read, create, update, or delete records in tables outside assigned module permissions due to improper access control in the table access voter. This issue is fixed in version 5.7.12. The vulnerability allows unauthorized data access, and defenders should prioritize patching to prevent exploitation. The issue arises from the TableAccessVoter::hasAccessToModule() function caching authorization decisions using only $tokenHash, omitting the table returned by getDataSource().

Vendor
contao
Product
Unknown
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders and administrators of Contao installations should assess exposure and prioritize patching to prevent unauthorized data access. They should review module permissions for low-privileged backend users and monitor for unauthorized access to sensitive tables. Security teams should verify and apply the patch to Contao version 5.7.12 and review compensating controls for exposed systems.

Why it matters

Defenders should care about CVE-2026-107851 as it allows low-privileged backend users to access sensitive data outside their module permissions in Contao. The issue requires verification of exposure and prompt patching to prevent unauthorized data access.

  • Potential unauthorized data access
  • Elevation of privileges for low-privileged users
  • Data tampering or deletion possible

Technical summary

The TableAccessVoter::hasAccessToModule() function in Contao caches authorization decisions using only $tokenHash, omitting the table returned by getDataSource(). This allows a low-privileged backend user to read, create, update, or delete records in tables outside assigned module permissions. The issue requires verification of exposure and prompt patching to prevent unauthorized data access. The vulnerability is fixed in Contao version 5.7.12, and defenders should prioritize applying the patch to prevent exploitation.

Defensive priority

Defenders should prioritize verifying and applying the patch to prevent unauthorized data access.

Recommended defensive actions

  • Verify and apply the patch to Contao version 5.7.12
  • Review and update module permissions for low-privileged backend users
  • Monitor for unauthorized access to sensitive tables
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability and its fix. The issue is confirmed in Contao versions 5.7.0 through 5.7.11. Defenders should verify exposure and apply the patch to prevent unauthorized data access. Evidence is based on the CVE Program record and source item details, with limitations on affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107851 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107851

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107851 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107851

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Contao: Improper access control in the table access voter

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107851.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/contao/contao/security/advisories/GHSA-5974-gfqc-wrcm

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/contao/contao/commit/9d6f582a4cc6a758ce11d1043fc9c0ba62c5f4c9

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/contao/contao/releases/tag/5.7.12

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.