SB2026082521 - Multiple vulnerabilities in Contao
Published: August 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 11 vulnerabilities.
1) Information disclosure (CVE-ID: N/A)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in ModuleSearch and the tl_search search index when returning search results after protected pages were indexed and the contao.search.index_protected setting is turned off. A remote attacker can perform search requests to disclose sensitive information.
The issue can expose member-only page titles, URLs, and indexed text in search results, while the protected pages themselves still return 401 responses.
2) Observable Response Discrepancy (CVE-ID: N/A)
CWE-ID: CWE-204 - Observable Response Discrepancy
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to observable response discrepancy in ModuleRegistration::compile() when handling POST requests to a page carrying the registration module. A remote attacker can send a specially crafted request to disclose sensitive information.
The issue can be used as an account oracle for whether an address has a pending registration on the site. Exploitation requires an unconfirmed registration state with tl_member.disable = 1 and an unconfirmed reg- opt-in token, and the branch is unreachable when reg_activate is off.
3) Cross-site request forgery (CVE-ID: N/A)
CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to perform unauthorized backend actions.
The vulnerability exists due to cross-site request forgery in custom backend actions when handling GET requests dispatched through parameters other than act. A remote user can trick a victim into loading a crafted URL to perform unauthorized backend actions.
User interaction is required, and the victim must be authenticated in the backend. Reachable actions are limited to modules the victim can access.
4) Path traversal (CVE-ID: N/A)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in ImagesController when handling crafted GET requests with percent-encoded dot segments in the {path} parameter. A remote attacker can send a specially crafted request to disclose sensitive information.
The issue is limited to files under the project directory whose names end in an allowed image extension, and on debug-enabled instances a 404 response may disclose the absolute filesystem path.
5) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary script in the victim's back end session and disclose sensitive information or modify data.
The vulnerability exists due to cross-site scripting in the comments bundle Comments module when rendering posted comments. A remote attacker can submit a comment containing a crafted script payload to execute arbitrary script in the victim's back end session and disclose sensitive information or modify data.
User interaction is required when a back end user opens the Comments module, and unpublished comments are still shown for moderation.
6) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the preview links module when handling preview link listings. A remote user can read preview links created by other users to disclose sensitive information.
Following a retrieved signed share URL grants front end preview of the target page with unpublished content visible and without a page permission check.
7) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the legacy search_default.html5 frontend search results template when rendering search results. A remote user can store a crafted title value that is later rendered through the raw link variable to execute arbitrary script in a victim's browser.
User interaction is required to view the search results page, and only instances using the legacy search_default.html5 template for the search module are vulnerable.
8) Improper privilege management (CVE-ID: N/A)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper privilege management in the user and group permission management functionality when modifying the themes permission field. A remote user can add the theme_import capability to their own or a managed account to execute arbitrary code.
The issue bypasses protections that only cover the modules field and the literal tpl_editor value, while the equally dangerous theme_import capability is exposed through the separate themes field.
9) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to overwrite arbitrary records outside their authorized scope.
The vulnerability exists due to improper access control in the CSV import wizard and Backend::getBackendModule() when dispatching custom backend module key actions. A remote user can send a crafted import action targeting records outside their scope to overwrite arbitrary records outside their authorized scope.
The issue affects non-admin editors scoped to certain pages or forms and results in blind content overwrite of tl_content or tl_form_field records.
10) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify newsletter channel data outside authorized channel scope.
The vulnerability exists due to improper access control in the newsletter module key-action handling when processing custom backend key-actions. A remote user can invoke crafted newsletter key-actions to modify newsletter recipients or send mail for channels they are not authorized to edit.
The issue affects channel-scoped newsletter editor workflows because per-record authorization checks are not enforced for these key-actions.
11) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information and perform unauthorized create, update, and delete operations on database tables outside their assigned permissions.
The vulnerability exists due to improper access control in the TableAccessVoter table access check when handling table-level permission checks within a single HTTP request. A remote user can trigger access checks for an allowed table and then access a different unauthorized table to disclose sensitive information and perform unauthorized create, update, and delete operations on database tables outside their assigned permissions.
The issue is caused by a cache key that omits the table being checked, allowing a previously cached authorization result to be reused for other tables during the same request.
Remediation
Install update from vendor's website.
References
- https://github.com/contao/contao/security/advisories/GHSA-x2rp-9qf7-2fmq
- https://github.com/contao/contao/security/advisories/GHSA-mfxh-vp55-7gc6
- https://github.com/contao/contao/security/advisories/GHSA-9ff2-p842-45wq
- https://github.com/contao/contao/security/advisories/GHSA-mrvp-7wmx-5m4h
- https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r
- https://github.com/contao/contao/security/advisories/GHSA-q6wp-fr43-gm9v
- https://github.com/contao/contao/security/advisories/GHSA-h57j-5f5m-789v
- https://github.com/contao/contao/security/advisories/GHSA-r9qp-pqx5-8369
- https://github.com/contao/contao/security/advisories/GHSA-23w9-4pg3-xwm3
- https://github.com/contao/contao/security/advisories/GHSA-3r9g-pfhv-3228
- https://github.com/contao/contao/security/advisories/GHSA-5974-gfqc-wrcm