Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 2.6 PHP packages GHSA-5974-gfqc-wrcm CVE-2026-107851 PKSA-b5qj-hq3z-3ry8

Contao: improper access control in TableAccessVoter (CVE-2026-107851)

A caching bug in contao/core-bundle's TableAccessVoter can let a low-privileged backend user access tables outside assigned module permissions; the issue is fixed in 5.7.12. (CVE-2026-107851)

AI summary

CVE-2026-107851 affects contao/core-bundle. A voter in Contao's security code cached authorization decisions incorrectly, which could permit backend users with limited privileges to operate on tables outside their assigned module permissions. A fixed release is available.

What happened

TableAccessVoter::hasAccessToModule() cached authorization decisions using only a token hash ($tokenHash) and omitted the table returned by getDataSource(). If a request first evaluated a permitted table and then a different denied table, the voter could reuse the permitted result; DefaultDataContainerVoter could then convert an incorrect abstention into a grant. The flaw allows a low-privileged backend user to read, create, update, or delete records in tables outside assigned module permissions, including tables holding member or newsletter-subscriber data.

Technical cause

The voter cached decisions keyed only by a hash of the user's security token and did not include the data-source table in the cache key. This allowed a cached 'allowed' decision from one table check to be reused for a different table check within the same request, producing incorrect authorization results.

Why it matters

A low-privileged backend user can gain access to records outside their module permissions. The advisory explicitly cites the ability to read, create, update, or delete records in tables the user should not access, with examples including member and newsletter-subscriber data.

Who is affected

The issue affects contao/core-bundle releases from 5.7.0 up to (but not including) 5.7.12. Users running those releases in backend environments may be exposed.

Affected versions

Introduced in 5.7.0 and fixed in 5.7.12; versions prior to 5.7.12 but at or after 5.7.0 are affected.

Fixes and mitigation

A vendor fix is available. The advisory lists 5.7.12 as the fixed release. The sources do not document alternative workarounds in place of the update.

Recommended action

Upgrade contao/core-bundle to the fixed release 5.7.12 as provided by the vendor. If you cannot apply the update immediately, restrict backend user privileges where possible and monitor access to sensitive tables until you can patch.

Discovery and timeline

The advisory entries and database records for this issue were published on 2026-10-09. Refer to the OSV, GitHub Advisory Database, Packagist advisory, and NVD entries for source timestamps and details.

PatchBriefing score

2.6 / 10 · Low

Official CVSS: 4.3

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Why this score

The CVSS v3.1 base score is 4.3 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N), indicating a low to medium severity with network attack vector but requiring low privileges. PatchWire's composite score is 2.6; contributing factors include the CVSS base score and the fact that no user interaction is required. There are no public exploits and no known exploitation reported in the advisory sources.

Affected versions

contao/core-bundle ≥ 5.7.0 < 5.7.12
vulnerable
contao/core-bundle
vulnerable
contao/core-bundle >=5.7.0,<5.7.12
vulnerable
contao/core-bundle >= 5.7.0, < 5.7.12
vulnerable
≥ 5.7.12
patched

Reported fixes

A vendor fix is available. The advisory lists 5.7.12 as the fixed release. The sources do not document alternative workarounds in place of the update.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • Packagist Security Advisories registry
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Contao: improper access control in TableAccessVoter (CVE-2026-107851)
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email