{"id":"CVE-2026-107851","title":"Contao is an Open Source CMS","summary":"Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-524","CWE-863"],"vendor":"contao","product":"contao/core-bundle","affected":["contao/core-bundle >= 5.7.0, < 5.7.12"],"patched":["contao/core-bundle 5.7.12"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T21:17:02.920","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107851","references":[{"url":"https://github.com/contao/contao/commit/9d6f582a4cc6a758ce11d1043fc9c0ba62c5f4c9","label":"security-advisories@github.com"},{"url":"https://github.com/contao/contao/releases/tag/5.7.12","label":"security-advisories@github.com"},{"url":"https://github.com/contao/contao/security/advisories/GHSA-5974-gfqc-wrcm","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-5974-gfqc-wrcm"}],"tags":["nvd","ghsa","composer"],"aliases":["GHSA-5974-gfqc-wrcm"],"ecosystem":"composer","ingestedAt":"2026-10-09T21:12:42.325Z","slug":"CVE-2026-107851","body":"## Overview\n\nContao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the user's security token, and omits the table returned by getDataSource(). If one request first checks a table allowed to the user and then a different denied table, the voter can reuse the allowed result, while DefaultDataContainerVoter can convert an incorrect abstention into a grant. A low-privileged backend user can consequently read, create, update, or delete records in tables outside assigned module permissions, including tables containing member or newsletter-subscriber data. This issue is fixed in version 5.7.12.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107851)\n\nAffected packages:\n\n- `contao/core-bundle >= 5.7.0, < 5.7.12`\n\nPatched in:\n\n- `contao/core-bundle 5.7.12`\n\nSource: https://github.com/advisories/GHSA-5974-gfqc-wrcm","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}