Description
Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the user's security token, and omits the table returned by getDataSource(). If one request first checks a table allowed to the user and then a different denied table, the voter can reuse the allowed result, while DefaultDataContainerVoter can convert an incorrect abstention into a grant. A low-privileged backend user can consequently read, create, update, or delete records in tables outside assigned module permissions, including tables containing member or newsletter-subscriber data. This issue is fixed in version 5.7.12.
Published: 2026-10-09
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from an improper use of caching in TableAccessVoter::hasAccessToModule(), which records authorization decisions using only a hashed token and ignores the database table being accessed. This allows a backend user to gain read, create, update, or delete privileges on tables outside of their assigned module permissions, potentially exposing member or newsletter-subscriber data. The flaw is an access control weakness that can enable privilege escalation and data leakage.

Affected Systems

Contao CMS, version 5.7.0 through 5.7.12. Any installation of these versions is affected; the issue was fixed in version 5.7.12.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a low‑privileged backend user exploiting the flawed token caching to access unauthorized tables. Once an authorizing request is made for an allowed table, a subsequent request for a disallowed table will be incorrectly granted due to the cached decision and conversion of an abstention into a grant by DefaultDataContainerVoter.

Generated by OpenCVE AI on October 9, 2026 at 21:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Contao to version 5.7.12 or later to remediate the flaw.
  • Restrict backend user roles to the minimum permissions required, especially for low‑privileged accounts, until the update is applied.
  • Audit database access logs and monitor for unauthorized table operations, and enforce stronger authentication on the backend to mitigate potential exploitation.

Generated by OpenCVE AI on October 9, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5974-gfqc-wrcm Contao: Improper access control in the table access voter
History

Fri, 09 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Contao
Contao contao
Vendors & Products Contao
Contao contao

Fri, 09 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
Description Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the user's security token, and omits the table returned by getDataSource(). If one request first checks a table allowed to the user and then a different denied table, the voter can reuse the allowed result, while DefaultDataContainerVoter can convert an incorrect abstention into a grant. A low-privileged backend user can consequently read, create, update, or delete records in tables outside assigned module permissions, including tables containing member or newsletter-subscriber data. This issue is fixed in version 5.7.12.
Title Contao: Improper access control in the table access voter
Weaknesses CWE-524
CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T20:26:31.329Z

Reserved: 2026-10-08T22:34:49.292Z

Link: CVE-2026-107851

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T21:17:02.920

Modified: 2026-10-09T21:17:02.920

Link: CVE-2026-107851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T21:30:12Z

Weaknesses
  • CWE-524

    Use of Cache Containing Sensitive Information

  • CWE-863

    Incorrect Authorization