Description
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12.
Published: 2026-10-09
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: Cross‑Site Request Forgery that can change system state via authenticated backend users
Action: Apply Patch
AI Analysis

Impact

Contao CMS implements a CSRF protection mechanism that validates the REQUEST_TOKEN only for POST requests, while the GET guard is triggered only when an act parameter is present. Backend operations dispatched through the key parameter can therefore be executed without a CSRF token when a legitimate backend user opens an attacker‑controlled URL. This flaw allows an attacker to induce the authenticated user to perform destructive or state‑changing actions such as deleting records, changing settings, or other administrative operations. The impact is limited to actions available to the user, so it does not grant privilege escalation but can compromise data integrity and availability.

Affected Systems

The vulnerability affects Contao CMS versions 4.0.0 through 5.3.49 and all releases prior to 5.7.12. Versions 5.3.50 and 5.7.12 contain the fix and are not vulnerable.

Risk and Exploitability

The CVSS score is 3.5, indicating a low severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a compromised or captive backend user being redirected to a malicious URL that relies on the GET request guard to trigger backend actions. Because the flaw requires an authenticated session, exploitation chances are moderate but the consequences are limited to the scope of the compromised account. Tailoring of the malicious URL remains essential for successful exploitation.

Generated by OpenCVE AI on October 9, 2026 at 21:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Contao 5.3.50 or later, or to 5.7.12 or later, which contain the CSRF guard fix for GET requests.
  • If an upgrade is not immediately possible, modify the application configuration or code so that CSRF token validation applies to all request methods used for backend actions, and disable processing of GET requests carrying the act or key parameters.
  • Implement or refine a web application firewall rule to block or require verification of GET requests targeting the Contao backend for authenticated sessions.
  • Continuously monitor backend logs for anomalous GET requests that include act or key parameters and treat them as potential exploitation attempts.

Generated by OpenCVE AI on October 9, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9ff2-p842-45wq Contao: Cross-site request forgery in custom backend actions
History

Fri, 09 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Contao
Contao contao
Vendors & Products Contao
Contao contao

Fri, 09 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
Description Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12.
Title Contao: Cross-site request forgery in custom backend actions
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T20:22:12.778Z

Reserved: 2026-10-08T22:34:49.291Z

Link: CVE-2026-107848

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T21:17:02.617

Modified: 2026-10-09T21:17:02.617

Link: CVE-2026-107848

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T21:30:12Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)