Description
Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when reg_activate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12.
Published: 2026-10-09
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Email Flood via Unauthenticated Activation Requests
Action: Immediate Patch
AI Analysis

Impact

The Contao registration module fails to verify that a form has been legitimately submitted or that a captcha challenge was completed. As a result, any unauthenticated POST to a page containing the module will trigger the resendActivationMail pathway, allowing an attacker to cause the system to send activation emails repeatedly to a target address. This lack of input validation and rate limiting permits an attacker to flood the target mailbox and to discover whether a pending registration exists. The flaw is identified as both an information‑leak weakness (CWE‑204) and an improper resource handling weakness (CWE‑770).

Affected Systems

Contao CMS instances running any version from 4.1.0 up to and including 5.3.50 and 5.7.12 are vulnerable. The vulnerability remains when the optional reg_activate feature is enabled and a user has a pending, unconfirmed registration with an opt‑in token. All other Contao versions are not affected by this issue.

Risk and Exploitability

The CVSS base score of 5.3 denotes a moderate impact. While the EPSS score is not available, the lack of authentication, captcha, or rate limiting means an attacker can easily trigger the flaw by repeatedly POSTing to the registration page. The vulnerability is not listed in CISA’s KEV catalog, but the straightforward exploitation path and the potential for large‑scale email flooding make timely remediation important.

Generated by OpenCVE AI on October 9, 2026 at 20:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Contao to version 5.3.50, 5.7.12, or any later release that includes the fix permanently applied to the registration module.
  • If an upgrade cannot be performed immediately, disable the registration module or block POST requests to pages that contain it until the patch is installed.
  • Verify that the reg_activate configuration remains enabled only for legitimate opt‑in flows and monitor email logs for abnormal activation email spikes to detect exploitation attempts.

Generated by OpenCVE AI on October 9, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Contao
Contao contao
Vendors & Products Contao
Contao contao

Fri, 09 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when reg_activate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12.
Title Contao: The registration module re-sends activation mails on any unauthenticated POST, with no throttle and no captcha check
Weaknesses CWE-204
CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T19:21:32.011Z

Reserved: 2026-10-08T22:34:49.291Z

Link: CVE-2026-107843

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T20:17:10.167

Modified: 2026-10-09T20:17:10.167

Link: CVE-2026-107843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T20:30:11Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy

  • CWE-770

    Allocation of Resources Without Limits or Throttling