Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 2.6 PHP packages GHSA-q6wp-fr43-gm9v CVE-2026-107850 PKSA-7n2q-445d-xssj

Contao: Improper access control in preview links (CVE-2026-107850)

A flaw in contao/core-bundle allows non-admin backend users with the preview_link module to list tl_preview_link records, obtain signed share URLs from other users, and view unpublished pages they lack permission for. The issue is fixed by the vendor in 5.7.12. (Sources: 3965, 4166, 8435, 32350)

AI summary

Contao's preview links functionality contains an authorization bypass that can let non-admin backend users view unpublished pages they should not be able to see. The problem affects contao/core-bundle between 5.7.1 and 5.7.12 and is fixed in 5.7.12. (Sources: 3965, 4166, 8435, 32350)

What happened

A bug in the preview links module allows a non-admin backend user who has the preview_link module to enumerate tl_preview_link records, obtain signed share URLs created by other users, and use those URLs to view unpublished pages with showUnpublished even when they lack page permission. The advisory explicitly does not establish that editing or deletion of foreign links is possible. (Sources: 3965, 4166, 8435, 32350)

Technical cause

services.yaml in contao/core-bundle registers the preview access voter under Contao\CoreBundle\Security\Voter\DataContainer\PreviewAccessVoter while the shipped class is named PreviewVoter. Because of this mismatch Symfony omits voter autoconfiguration and removes the private service, so PreviewVoter::hasAccess() is not invoked to enforce ownership checks. (Sources: 3965, 4166, 8435)

Why it matters

The flaw is an authorization bypass that leads to unauthorized viewing of unpublished content. The NVD entry and advisories report confidentiality impact only; there is no reported integrity or availability impact. (Sources: 3965, 8435, 32350)

Who is affected

The issue affects contao/core-bundle from 5.7.1 up to and including 5.7.12 (fixed in 5.7.12). Non-admin backend users who have the preview_link module are the actors who can exploit the issue to view unpublished pages they do not own. (Sources: 3965, 4166, 8435)

Discovery and timeline

Public advisory and database entries were published on 2026-10-09. OSV.dev and GitHub Advisory Database entries list 2026-10-09 as the publication date, and the NVD entry was published on 2026-10-09 (UTC offsets in source metadata). The sources do not provide additional discovery or researcher credit information. (Sources: 3965, 4166, 8435, 32350)

Affected versions

contao/core-bundle versions from 5.7.1 through 5.7.12 are cited as the affected range, and the vendor-provided fix is published in 5.7.12. (Sources: 3965, 4166, 8435)

Fixes and mitigation

A vendor fix is available; the vulnerability is fixed in contao/core-bundle 5.7.12. The published advisories do not list other mitigation steps or workarounds. (Sources: 3965, 8435)

Recommended action

Update contao/core-bundle to 5.7.12 to obtain the vendor fix. The advisories do not provide additional mitigation guidance; review backend user privileges for preview_link access as an operational precaution if you cannot apply the update immediately. (Sources: 3965, 8435)

PatchBriefing score

2.6 / 10 · Low

Official CVSS: 4.3

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Why this score

CVSS v3.1 base score 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) indicates a low-to-medium severity with network attack vector and required low-privileged authenticated access. PatchWire score is 2.6; contributing factors include the CVSS base and that no user interaction is required. Public exploitation and known exploitation flags are false in the sources. (Sources: 3965, 8435, 32350)

Affected versions

contao/core-bundle ≥ 5.7.1 < 5.7.12
vulnerable
contao/core-bundle
vulnerable
contao/core-bundle >=5.7.1,<5.7.12
vulnerable
contao/core-bundle >= 5.7.1, < 5.7.12
vulnerable
≥ 5.7.12
patched

Reported fixes

A vendor fix is available; the vulnerability is fixed in contao/core-bundle 5.7.12. The published advisories do not list other mitigation steps or workarounds. (Sources: 3965, 8435)

How this was built

4 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • Packagist Security Advisories registry
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Contao: Improper access control in preview links (CVE-2026-107850)
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email