Description
Contao is an Open Source CMS. From version 5.7.1 until 5.7.12, core-bundle/config/services.yaml registers the preview access voter as Contao\CoreBundle\Security\Voter\DataContainer\PreviewAccessVoter although the shipped class is PreviewVoter. Symfony therefore omits voter autoconfiguration and removes the private service, so PreviewVoter::hasAccess() never enforces ownership. A non-admin backend user with the preview_link module can list every tl_preview_link record, obtain signed share URLs created by other users, and use them to view unpublished pages with showUnpublished despite lacking page permission. The advisory does not establish editing or deletion of foreign links. This issue is fixed in version 5.7.12.
Published: 2026-10-09
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized disclosure of unpublished content
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a misconfiguration of the Symfony voter system in Contao CMS versions 5.7.1 through 5.7.12. The preview access voter is registered under the wrong class name, causing the ownership check to be bypassed. As a result, any non‑admin backend user who has the preview_link module enabled can list all tl_preview_link records, retrieve signed URLs created by other users, and use those URLs to view unpublished pages without proper page permissions. The flaw allows disclosure of unpublished content but does not enable editing or deletion of the links.

Affected Systems

Contao installations running any version from 5.7.1 up to and including 5.7.12 are affected. Versions before 5.7.1 and the release that fixed the bug, 5.7.12 and later, are not impacted. The issue is specific to the core bundle’s services.yaml where the voter class is incorrectly referenced.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited evidence of exploitation. Attackers can exercise this flaw only if they have valid backend credentials and the preview_link module enabled for their account; thus the attack surface is confined to authorized users of the CMS. Because the exploit requires no special network access or privileges beyond those already held by the user, the overall risk is considered moderate but only relevant to environments where non‑admin users are granted preview_link access.

Generated by OpenCVE AI on October 9, 2026 at 21:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Contao to version 5.7.12 or later, where the preview access voter is correctly configured.
  • If an upgrade cannot be performed immediately, disable the preview_link module for all non‑admin users or remove the module entirely to prevent creation or use of preview links.
  • Review backend user permissions to ensure that only administrators or trusted users have access to the preview_link module, mitigating accidental exposure of unpublished pages.

Generated by OpenCVE AI on October 9, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q6wp-fr43-gm9v Contao: Improper access control in the preview links module
History

Fri, 09 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Contao
Contao contao
Vendors & Products Contao
Contao contao

Fri, 09 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
Description Contao is an Open Source CMS. From version 5.7.1 until 5.7.12, core-bundle/config/services.yaml registers the preview access voter as Contao\CoreBundle\Security\Voter\DataContainer\PreviewAccessVoter although the shipped class is PreviewVoter. Symfony therefore omits voter autoconfiguration and removes the private service, so PreviewVoter::hasAccess() never enforces ownership. A non-admin backend user with the preview_link module can list every tl_preview_link record, obtain signed share URLs created by other users, and use them to view unpublished pages with showUnpublished despite lacking page permission. The advisory does not establish editing or deletion of foreign links. This issue is fixed in version 5.7.12.
Title Contao: Improper access control in the preview links module
Weaknesses CWE-639
CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T20:25:02.286Z

Reserved: 2026-10-08T22:34:49.292Z

Link: CVE-2026-107850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T21:17:02.770

Modified: 2026-10-09T21:17:02.770

Link: CVE-2026-107850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T21:30:12Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-862

    Missing Authorization