Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107843— Contao: The registration module re-sends activation mails on any unauthenticated POST, with no throttle and no captcha check

Quick assessment

Affected
contao contao
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Contao 是一款开源内容管理系统(CMS)。在版本 4.1.0 至 5.3.50 以及 5.7.0 至 5.7.12 之间,当对包含注册模块的页面发起 POST 请求时, 方法会进入后续的注册处理分支,但并未验证 字段或之前提交的验证码结果。这可能导致 方法调用 发送激活邮件,且该过程缺乏速率限制。因此,未认证的攻击者可以向具有待处理注册状态的邮箱地址重复发送激活邮件,并借此判断该待处理注册是否存在。 此漏洞仅在启用 (注册激活)功能、且目标用户存在未确认的注册记录和待处理的光标选择(opt-in)令牌时才可触

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1595 · Active Scanning

Affected Version Matrix 2

VendorProduct Version RangeStatus
contao contao >= 4.1.0, < 5.3.50 affected
>= 5.4.0-RC1, < 5.7.12 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107843

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Contao: The registration module re-sends activation mails on any unauthenticated POST, with no throttle and no captcha check
Source: CVE Program / CVE List V5
Vulnerability Description
Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when reg_activate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
响应差异性信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
contao contao >= 4.1.0, < 5.3.50 -

II. Public POCs for CVE-2026-107843

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107843

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107843 (1)

Vendor Advisories for CVE-2026-107843 (1)

Vendor Pages for CVE-2026-107843 (2)

Same Patch Batch · contao · 2026-10-09 · 7 CVEs total

CVE-2026-107845 9.3 CRITICAL Contao: Cross-site scripting in the comments bundle
CVE-2026-107842 5.3 MEDIUM Contao: Protected page content is disclosed to anonymous visitors after contao.search.inde
CVE-2026-107844 5.3 MEDIUM Contao: Path traversal in the images controller
CVE-2026-107851 4.3 MEDIUM Contao: Improper access control in the table access voter
CVE-2026-107850 4.3 MEDIUM Contao: Improper access control in the preview links module
CVE-2026-107848 3.5 LOW Contao: Cross-site request forgery in custom backend actions

IV. Related Vulnerabilities

V. Comments for CVE-2026-107843

No comments yet


Leave a comment