{"id":"CVE-2026-107848","title":"Contao is an Open Source CMS","summary":"Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions di…","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-352"],"vendor":"contao","product":"contao/core-bundle","affected":["contao/core-bundle >= 4.0.0, < 5.3.50","contao/core-bundle >= 5.4.0-RC1, < 5.7.12"],"patched":["contao/core-bundle 5.3.50","contao/core-bundle 5.7.12"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T21:17:02.617","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107848","references":[{"url":"https://github.com/contao/contao/commit/34dd27ee6739f10568d3d95d8784862255c925b4","label":"security-advisories@github.com"},{"url":"https://github.com/contao/contao/releases/tag/5.7.12","label":"security-advisories@github.com"},{"url":"https://github.com/contao/contao/security/advisories/GHSA-9ff2-p842-45wq","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-9ff2-p842-45wq"}],"tags":["nvd","ghsa","composer"],"aliases":["GHSA-9ff2-p842-45wq"],"ecosystem":"composer","ingestedAt":"2026-10-09T21:12:42.325Z","slug":"CVE-2026-107848","body":"## Overview\n\nContao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107848)\n\nAffected packages:\n\n- `contao/core-bundle >= 4.0.0, < 5.3.50`\n- `contao/core-bundle >= 5.4.0-RC1, < 5.7.12`\n\nPatched in:\n\n- `contao/core-bundle 5.3.50`\n- `contao/core-bundle 5.7.12`\n\nSource: https://github.com/advisories/GHSA-9ff2-p842-45wq","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}