CVE-2026-107848: Contao

Low severity, CVSS 3.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12.

Affected products

  • Contao Contao: from 4.0.0, before 5.3.50 (fixed in 5.3.50); from 5.4.0-RC1, before 5.7.12 (fixed in 5.7.12)

Published 2026-10-09. Last modified 2026-10-09.