Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 1.9 PHP packages GHSA-9ff2-p842-45wq CVE-2026-107848 PKSA-6ymc-kdpm-qx87

CVE-2026-107848 — Contao: CSRF in backend actions

Contao contains a cross-site request forgery (CSRF) bug that allows authenticated backend users to trigger state-changing backend actions via specially crafted URLs. The issue is fixed in 5.3.50 and 5.7.12. (CVE-2026-107848, GHSA-9ff2-p842-45wq).

AI summary

CVE-2026-107848 (GHSA-9ff2-p842-45wq, PKSA-6ymc-kdpm-qx87) affects contao/core-bundle. A CSRF validation gap can let an attacker cause state-changing backend actions to run when an authenticated backend user visits an attacker-controlled URL. Sources: OSV, GitHub Advisory Database, Packagist Security Advisories, NVD.

What happened

Contao's RequestTokenListener validated REQUEST_TOKEN only for POST requests while the declarative GET guard ran only when an act parameter was present. Backend actions dispatched through the key parameter could therefore execute without a CSRF token if an authenticated backend user loaded an attacker-controlled URL. Reachable actions are limited to modules available to that user; the advisory demonstrates destructive or other state-changing actions rather than privilege escalation.

Technical cause

The vulnerability arises from inconsistent enforcement of CSRF checks: token validation applied only to POST requests, and the GET-side declarative guard only applied when an act parameter was present. Actions triggered via a different parameter (key) bypassed the GET guard, allowing state-changing backend operations to be invoked without a REQUEST_TOKEN when a backend user followed a crafted link.

Why this matters

An attacker who can cause an authenticated backend user to load a crafted URL may trigger state changes or destructive backend actions within the scope of that user's module privileges. The issue does not, in the available advisory material, represent unauthenticated remote access or direct privilege escalation, but it impacts integrity by enabling actions without a CSRF token.

Who is affected

Installs of contao/core-bundle in the vulnerable ranges are affected. The behavior requires an authenticated backend user — actions invoked are limited to the modules accessible to that user.

Discovery and timeline

Advisories and database entries publishing this issue appeared on 2026-10-09 (OSV/GitHub advisory entries). The NVD entry is published and referenced with a later modification timestamp on 2026-10-09. See the source advisories for full timestamps.

Affected versions

Sources describe the vulnerability affecting contao/core-bundle from 4.0.0 up to 5.3.50, and from 5.4.0-RC1 up to 5.7.12. Vendor fixes are provided in 5.3.50 and 5.7.12.

Fixes and mitigation

Vendor fixes are available; the issue is fixed in 5.3.50 and in 5.7.12. The published sources indicate updates as the remediation. The advisories do not list other compensating mitigations in detail.

Recommended action

Apply the vendor update to a fixed release — upgrade affected contao/core-bundle installations to 5.3.50 or 5.7.12 as appropriate for your deployment. Review backend module access and limit backend user exposure to untrusted links until systems are patched.

PatchBriefing score

1.9 / 10 · Low

Official CVSS: 3.5

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Why this score

CVSS v3.1 base score is 3.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N), indicating a low base severity driven by required user interaction and limited impact to integrity only. PatchWire score is 1.9; the primary contribution to that score is the CVSS base value, with no contribution from known exploitation or public exploit data in the sources.

Affected versions

contao/core-bundle ≥ 5.4.0-RC1 < 5.7.12
vulnerable
contao/core-bundle
vulnerable
contao/core-bundle >=5.4.0-RC1,<5.7.12|>=4.0.0,<5.3.50
vulnerable
contao/core-bundle >= 5.4.0-RC1, < 5.7.12
vulnerable
≥ 5.3.50
patched
≥ 5.7.12
patched

Reported fixes

Vendor fixes are available; the issue is fixed in 5.3.50 and in 5.7.12. The published sources indicate updates as the remediation. The advisories do not list other compensating mitigations in detail.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • Packagist Security Advisories registry
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
CVE-2026-107848 — Contao: CSRF in backend actions
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email