AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-107848.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSLOW / 3.5CVSS 3.1 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSReceivedModified Oct 09, 2026

Disclosure summary

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12.

Source-reported weakness categories

CWE-352

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-107848

Open original source · Updated Oct 09, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

GitHub Reviewed Security Advisories · GHSA-9ff2-p842-45wq

Open original source · Updated Oct 09, 2026

Contao: Cross-site request forgery in custom backend actions

Source severity: LOW / 0

EcosystemPackageAffected rangeFirst patched
composercontao/core-bundle>= 4.0.0, < 5.3.505.3.50
composercontao/core-bundle>= 5.4.0-RC1, < 5.7.125.7.12

Original records & references

PUBLISHED 2026-10-09T17:17:02-04:00
MODIFIED 2026-10-09T17:17:02-04:00
INGESTED 2026-10-10T20:55:12-04:00