PT-2026-109306 · Contao · Contao

CVE-2026-107848

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Contao versions 4.0.0 through 5.3.49 Contao versions 5.7.0 through 5.7.11
Description Cross-Site Request Forgery (CSRF) occurs because the RequestTokenListener function validates the REQUEST TOKEN only for POST requests. While a declarative GET guard exists, it only executes when an act parameter is present. Consequently, backend actions dispatched via the key parameter can be executed without a CSRF token if an authenticated backend user loads an attacker-controlled URL. This allows an attacker to perform state-changing or destructive actions on behalf of the authenticated user, limited to the modules the user has permission to access.
Recommendations Update to version 5.3.50. Update to version 5.7.12.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107848
GHSA-9FF2-P842-45WQ

Affected Products

Contao