Disclosure summary
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12.
Source-reported weakness categories
CWE-352
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107848
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-9ff2-p842-45wq
Open original source · Updated Oct 09, 2026
Contao: Cross-site request forgery in custom backend actions
Source severity: LOW / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| composer | contao/core-bundle | >= 4.0.0, < 5.3.50 | 5.3.50 |
| composer | contao/core-bundle | >= 5.4.0-RC1, < 5.7.12 | 5.7.12 |
Original records & references
PUBLISHED 2026-10-09T17:17:02-04:00
MODIFIED 2026-10-09T17:17:02-04:00
INGESTED 2026-10-10T20:55:12-04:00