PT-2026-109302 · Contao · Contao

CVE-2026-107843

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Contao versions 4.1.0 through 5.3.49 Contao versions 5.7.0 through 5.7.11
Description An issue exists where the ModuleRegistration::compile() function enters its follow-up registration branch on any POST request to a page containing the registration module without verifying FORM SUBMIT or the preceding captcha result. This allows an unauthenticated attacker to trigger the resendActivationMail() function, which invokes OptInToken::send() without rate limiting. Consequently, an attacker can cause repeated activation emails to be sent to an address with a pending registration and determine if such a registration exists. This behavior occurs when reg activate is enabled and the target has an unconfirmed registration and opt-in token. This can lead to a deliverability risk for the site operator and the disclosure of membership status.
Recommendations Update to version 5.3.50. Update to version 5.7.12.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107843
GHSA-MFXH-VP55-7GC6

Affected Products

Contao