Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 3.7 PHP packages GHSA-x2rp-9qf7-2fmq CVE-2026-107842 PKSA-bmqh-y7sv-p1st

Contao search index disclosure — CVE-2026-107842

A Contao search module can disclose protected page titles, URLs and indexed snippets to unauthenticated visitors when contao.search.index_protected is switched from enabled to disabled. Fixed in vendor updates.

AI summary

The Contao content management system has a search-index disclosure (CVE-2026-107842). Under certain configuration changes the search index can expose protected page metadata and indexed text to unauthenticated visitors. Fixes are available from the vendor.

What happened

ModuleSearch in Contao can disclose protected page titles, URLs and indexed context snippets to unauthenticated visitors when the configuration contao.search.index_protected is changed from enabled to disabled. The issue exposes search metadata and indexed text rather than bypassing page access controls. (Sources: 3964, 4170, 8440, 32344)

Technical cause

Authorization metadata for search rows is stored per row in tl_search. Disabling contao.search.index_protected removes the protected-row filter from search queries but does not delete rows that were indexed while protection was enabled. Because protected pages still return an authorization response, the behaviour results in exposure of search metadata and indexed snippets rather than direct page access bypass. (Sources: 3964, 4170, 8440)

Why this matters

Unauthenticated visitors can learn page titles, URLs and parts of the indexed content for pages that were intended to remain protected. The vulnerability is scored CVSS 3.1 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). The PatchWire composite score for prioritization is 3.7, which includes contributions for unauthenticated remote access and no user interaction. (Sources: 3964, 32344)

Who is affected

Installations of contao/core-bundle whose search indexing setting contao.search.index_protected was enabled and later changed to disabled are exposed. The advisory lists the affected ranges for contao/core-bundle as versions from 4.0.0 up to 5.3.50, and from 5.4.0-RC1 up to 5.7.12 (see affected versions). Confirm whether your installed package falls into these ranges. (Sources: 3964, 4170, 8440)

Discovery and timeline

The advisory was published 2026-10-09; entries for this vulnerability appear in OSV, GitHub Advisory Database / Packagist Security Advisories and NVD on that date. (Sources: 3964, 4170, 8440, 32344)

Affected and fixed versions

According to the advisory, contao/core-bundle is affected in these ranges: >= 4.0.0, < 5.3.50 and >= 5.4.0-RC1, < 5.7.12. The vendor provided fixes are in versions 5.3.50 and 5.7.12. Verify your installed package against these ranges. (Sources: 3964, 4170, 8440)

Fixes and mitigation

A vendor fix is available. The advisory lists fixed versions 5.3.50 and 5.7.12 for contao/core-bundle. No additional vendor mitigation steps are included in the supplied advisory text. (Sources: 3964, 8440)

Recommended action

Apply the vendor update to contao/core-bundle: upgrade to one of the fixed versions listed by the vendor (5.3.50 or 5.7.12). If you have changed contao.search.index_protected from enabled to disabled, check whether your deployment falls into the affected ranges before and after the change. (Sources: 3964, 8440)

PatchBriefing score

3.7 / 10 · Low

Official CVSS: 5.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Why this score

The advisory lists a CVSS 3.1 base score of 5.3 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). The PatchWire prioritization score is 3.7; its contributors include the CVSS base and the fact that the issue can be triggered remotely without authentication and without user interaction. Public exploit or known exploitation are not reported in the advisory. (Sources: 3964, 32344)

Affected versions

contao/core-bundle ≥ 5.4.0-RC1 < 5.7.12
vulnerable
contao/core-bundle
vulnerable
contao/core-bundle >=5.4.0-RC1,<5.7.12|>=4.0.0,<5.3.50
vulnerable
contao/core-bundle >= 5.4.0-RC1, < 5.7.12
vulnerable
≥ 5.3.50
patched
≥ 5.7.12
patched

Reported fixes

A vendor fix is available. The advisory lists fixed versions 5.3.50 and 5.7.12 for contao/core-bundle. No additional vendor mitigation steps are included in the supplied advisory text. (Sources: 3964, 8440)

How this was built

4 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • Packagist Security Advisories registry
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Contao search index disclosure — CVE-2026-107842
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email