Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107851— Contao: Improper access control in the table access voter

Quick assessment

Affected
contao contao
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Contao 是一个开源的内容管理系统(CMS)。在版本 5.7.0 至 5.7.12 中, 中的 方法在缓存授权决策时仅使用了 (用户安全令牌的哈希值),而忽略了 返回的数据表信息。因此,如果一个请求先检查了用户有权访问的某个数据表,随后又检查另一个用户无权访问的数据表,该投票器(Voter)可能会错误地重用之前“允许访问”的缓存结果;同时, 可能将本应返回的“弃权”(abstention)错误地转换为“允许访问”(grant)。这导致具有低权限的后端用户能够读写、创建、更新或删除超出其模块权限范围的数据表中的记

CVSS 4.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107851

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Contao: Improper access control in the table access voter
Source: CVE Program / CVE List V5
Vulnerability Description
Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the user's security token, and omits the table returned by getDataSource(). If one request first checks a table allowed to the user and then a different denied table, the voter can reuse the allowed result, while DefaultDataContainerVoter can convert an incorrect abstention into a grant. A low-privileged backend user can consequently read, create, update, or delete records in tables outside assigned module permissions, including tables containing member or newsletter-subscriber data. This issue is fixed in version 5.7.12.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过缓存导致的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
contao contao >= 5.7.0, < 5.7.12 -

II. Public POCs for CVE-2026-107851

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107851

请登录查看更多情报信息。

Vendor Pages for CVE-2026-107851 (1)

Other References for CVE-2026-107851 (2)

Same Patch Batch · contao · 2026-10-09 · 7 CVEs total

CVE-2026-107845 9.3 CRITICAL Contao: Cross-site scripting in the comments bundle
CVE-2026-107842 5.3 MEDIUM Contao: Protected page content is disclosed to anonymous visitors after contao.search.inde
CVE-2026-107844 5.3 MEDIUM Contao: Path traversal in the images controller
CVE-2026-107843 5.3 MEDIUM Contao: The registration module re-sends activation mails on any unauthenticated POST, wit
CVE-2026-107850 4.3 MEDIUM Contao: Improper access control in the preview links module
CVE-2026-107848 3.5 LOW Contao: Cross-site request forgery in custom backend actions

IV. Related Vulnerabilities

V. Comments for CVE-2026-107851

No comments yet


Leave a comment