---
id: CVE-2026-107851
title: Contao is an Open Source CMS
summary: >-
  Contao is an Open Source CMS. From version 5.7.0 until 5.7.12,
  TableAccessVoter::hasAccessToModule() in
  core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches
  authorization decisions using only $tokenHash, a hash of the…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-524
  - CWE-863
vendor: contao
product: contao/core-bundle
affected:
  - 'contao/core-bundle >= 5.7.0, < 5.7.12'
patched:
  - contao/core-bundle 5.7.12
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T21:17:02.920'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107851'
references:
  - url: >-
      https://github.com/contao/contao/commit/9d6f582a4cc6a758ce11d1043fc9c0ba62c5f4c9
    label: security-advisories@github.com
  - url: 'https://github.com/contao/contao/releases/tag/5.7.12'
    label: security-advisories@github.com
  - url: 'https://github.com/contao/contao/security/advisories/GHSA-5974-gfqc-wrcm'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-5974-gfqc-wrcm'
tags:
  - nvd
  - ghsa
  - composer
aliases:
  - GHSA-5974-gfqc-wrcm
ecosystem: composer
ingestedAt: '2026-10-09T21:12:42.325Z'
---

## Overview

Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the user's security token, and omits the table returned by getDataSource(). If one request first checks a table allowed to the user and then a different denied table, the voter can reuse the allowed result, while DefaultDataContainerVoter can convert an incorrect abstention into a grant. A low-privileged backend user can consequently read, create, update, or delete records in tables outside assigned module permissions, including tables containing member or newsletter-subscriber data. This issue is fixed in version 5.7.12.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107851)

Affected packages:

- `contao/core-bundle >= 5.7.0, < 5.7.12`

Patched in:

- `contao/core-bundle 5.7.12`

Source: https://github.com/advisories/GHSA-5974-gfqc-wrcm
