{"id":"CVE-2026-107843","title":"Contao is an Open Source CMS","summary":"Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or th…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-204","CWE-770"],"vendor":"contao","product":"contao/core-bundle","affected":["contao/core-bundle >= 4.1.0, < 5.3.50","contao/core-bundle >= 5.4.0-RC1, < 5.7.12"],"patched":["contao/core-bundle 5.3.50","contao/core-bundle 5.7.12"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T20:17:10.167","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107843","references":[{"url":"https://github.com/contao/contao/commit/2ea6117f9049db7221679251cfc41e67d941a74b","label":"security-advisories@github.com"},{"url":"https://github.com/contao/contao/releases/tag/5.3.50","label":"security-advisories@github.com"},{"url":"https://github.com/contao/contao/releases/tag/5.7.12","label":"security-advisories@github.com"},{"url":"https://github.com/contao/contao/security/advisories/GHSA-mfxh-vp55-7gc6","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-mfxh-vp55-7gc6"}],"tags":["nvd","ghsa","composer"],"aliases":["GHSA-mfxh-vp55-7gc6"],"ecosystem":"composer","ingestedAt":"2026-10-09T21:12:42.318Z","slug":"CVE-2026-107843","body":"## Overview\n\nContao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when reg_activate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107843)\n\nAffected packages:\n\n- `contao/core-bundle >= 4.1.0, < 5.3.50`\n- `contao/core-bundle >= 5.4.0-RC1, < 5.7.12`\n\nPatched in:\n\n- `contao/core-bundle 5.3.50`\n- `contao/core-bundle 5.7.12`\n\nSource: https://github.com/advisories/GHSA-mfxh-vp55-7gc6","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}