Low · 3.7 PHP packages GHSA-x2rp-9qf7-2fmq CVE-2026-107842 PKSA-bmqh-y7sv-p1st
Contao search index disclosure — CVE-2026-107842
A Contao search module can disclose protected page titles, URLs and indexed snippets to unauthenticated visitors when contao.search.index_protected is switched from enabled to disabled. Fixed in vendor updates.
AI summary
The Contao content management system has a search-index disclosure (CVE-2026-107842). Under certain configuration changes the search index can expose protected page metadata and indexed text to unauthenticated visitors. Fixes are available from the vendor.
What happened
ModuleSearch in Contao can disclose protected page titles, URLs and indexed context snippets to unauthenticated visitors when the configuration contao.search.index_protected is changed from enabled to disabled. The issue exposes search metadata and indexed text rather than bypassing page access controls. (Sources: 3964, 4170, 8440, 32344)
Technical cause
Authorization metadata for search rows is stored per row in tl_search. Disabling contao.search.index_protected removes the protected-row filter from search queries but does not delete rows that were indexed while protection was enabled. Because protected pages still return an authorization response, the behaviour results in exposure of search metadata and indexed snippets rather than direct page access bypass. (Sources: 3964, 4170, 8440)
Why this matters
Unauthenticated visitors can learn page titles, URLs and parts of the indexed content for pages that were intended to remain protected. The vulnerability is scored CVSS 3.1 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). The PatchWire composite score for prioritization is 3.7, which includes contributions for unauthenticated remote access and no user interaction. (Sources: 3964, 32344)
Who is affected
Installations of contao/core-bundle whose search indexing setting contao.search.index_protected was enabled and later changed to disabled are exposed. The advisory lists the affected ranges for contao/core-bundle as versions from 4.0.0 up to 5.3.50, and from 5.4.0-RC1 up to 5.7.12 (see affected versions). Confirm whether your installed package falls into these ranges. (Sources: 3964, 4170, 8440)
Discovery and timeline
The advisory was published 2026-10-09; entries for this vulnerability appear in OSV, GitHub Advisory Database / Packagist Security Advisories and NVD on that date. (Sources: 3964, 4170, 8440, 32344)
Affected and fixed versions
According to the advisory, contao/core-bundle is affected in these ranges: >= 4.0.0, < 5.3.50 and >= 5.4.0-RC1, < 5.7.12. The vendor provided fixes are in versions 5.3.50 and 5.7.12. Verify your installed package against these ranges. (Sources: 3964, 4170, 8440)
Fixes and mitigation
A vendor fix is available. The advisory lists fixed versions 5.3.50 and 5.7.12 for contao/core-bundle. No additional vendor mitigation steps are included in the supplied advisory text. (Sources: 3964, 8440)
Recommended action
Apply the vendor update to contao/core-bundle: upgrade to one of the fixed versions listed by the vendor (5.3.50 or 5.7.12). If you have changed contao.search.index_protected from enabled to disabled, check whether your deployment falls into the affected ranges before and after the change. (Sources: 3964, 8440)
PatchBriefing score
3.7 / 10 · Low
Official CVSS: 5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Why this score
The advisory lists a CVSS 3.1 base score of 5.3 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). The PatchWire prioritization score is 3.7; its contributors include the CVSS base and the fact that the issue can be triggered remotely without authentication and without user interaction. Public exploit or known exploitation are not reported in the advisory. (Sources: 3964, 32344)
Affected versions
- contao/core-bundle ≥ 5.4.0-RC1 < 5.7.12
- vulnerable
- contao/core-bundle
- vulnerable
- contao/core-bundle >=5.4.0-RC1,<5.7.12|>=4.0.0,<5.3.50
- vulnerable
- contao/core-bundle >= 5.4.0-RC1, < 5.7.12
- vulnerable
- ≥ 5.3.50
- patched
- ≥ 5.7.12
- patched
Reported fixes
A vendor fix is available. The advisory lists fixed versions 5.3.50 and 5.7.12 for contao/core-bundle. No additional vendor mitigation steps are included in the supplied advisory text. (Sources: 3964, 8440)
How this was built
4 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
Packagist Security Advisories registry
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email