Vulnerability GHSA-5974-gfqc-wrcm

Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 hours ago
October 09, 2026 at 08:53 PM UTC
Contao: Improper access control in the table access voter
5.7.0 - 5.7.11
5.7.0 - 5.7.11

Summary

Contao: Improper access control in the table access voter

Details

Due to a caching defect in the security voter that governs table-level access to Contao's Data Container (DCA) backend, a low-privileged, non-admin backend user can obtain unauthorized read, create, update, and delete access to database tables outside their assigned module permissions. This includes tables containing sensitive personal data, such as frontend member records and newsletter subscriber e-mail addresses.

Vulnerability Details

In plain terms: Contao's backend is organized into modules (e.g. "News", "Members"). Every backend user is assigned to a group, and that group decides which modules, and therefore which database tables, they are allowed to work with. Before Contao lets a user touch a table, it is supposed to check: "does this user's group actually include this table?"

To avoid doing that check over and over, Contao remembers the answer for the rest of the request. The problem is that it remembers the answer under the wrong label. Instead of remembering "is this user allowed to access table X", it only remembers "is this user allowed to access something", without recording which table the answer was actually about.

So if a request first checks a table the user IS allowed to see, and then checks a second, completely different table the user is NOT allowed to see, Contao reuses the first answer for the second table too. The user ends up with access to a table their group was never given permission for.

Technical detail

Contao's backend enforces per-table access control through a chain of Symfony security voters. The relevant one is TableAccessVoter::hasAccessToModule(), in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php:

    private array $canAccessTable = [];
    private array $canReadAccessTable = [];
 
    private function hasAccessToModule(TokenInterface $token, ...): bool
    {
        $tokenHash = hash('xxh128', serialize($token));
 
        if (isset($this->canAccessTable[$tokenHash]) || (...)) {
            return $this->canAccessTable[$tokenHash] ?? $this->canReadAccessTable[$tokenHash];
        }
 
        $table = $subject->getDataSource();
 
        foreach ($GLOBALS['BE_MOD'] as $modules) {
            ...
            return $this->canAccessTable[$tokenHash] = true;  // or false
        }
    }

The cache key, $tokenHash, is built only from the current user's security token. It does not include the table being checked. Because TableAccessVoter is a normal, shared Symfony service, this cache stays alive for the whole duration of one HTTP request. So the first table checked for a user in a request decides the cached answer for every other table checked afterwards in that same request, whether or not that answer is actually correct for the second table.

This is made worse by DefaultDataContainerVoter, a low-priority, permissive fallback voter that grants access to any table-related permission unless another voter explicitly denies it. When TableAccessVoter gives a wrong "no opinion" answer because of the stale cache, this fallback voter turns that into a full grant.

Most database tables in Contao have no second, table-specific check to catch this. Only tl_content, tl_favorites, tl_form, tl_form_field, tl_module, tl_image_size(_item), tl_job, tl_layout, tl_page, tl_preview_link, tl_undo, and tl_user have one. Tables such as tl_member (website member data), tl_newsletter_recipients (subscriber e-mail addresses), tl_news, tl_calendar_events, tl_faq, and tl_comments rely only on the defective check described above.

Credits

This security vulnerability was found by Sven Jäger of SySS GmbH.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
3 hours ago
Contao: Protected page content is disclosed to anonymous visitors after contao.search.index_protected is disabled
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.49 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.11 GHSA-x2rp-9qf7-2fmq
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.49 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.11 GHSA-x2rp-9qf7-2fmq
Medium Risk
3 hours ago
Contao: The registration module re-sends activation mails
4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.49 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.11 GHSA-mfxh-vp55-7gc6
4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.49 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.11 GHSA-mfxh-vp55-7gc6
Low Risk
3 hours ago
Contao: Cross-site request forgery in custom backend actions
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.49 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.11 GHSA-9ff2-p842-45wq
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.49 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.11 GHSA-9ff2-p842-45wq
Medium Risk
3 hours ago
Contao: Path traversal in the images controller
4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.49 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.11 GHSA-mrvp-7wmx-5m4h
4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.49 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.11 GHSA-mrvp-7wmx-5m4h
Medium Risk
3 hours ago
Contao: Improper access control in the preview links module
5.7.1 - 5.7.11 GHSA-q6wp-fr43-gm9v
5.7.1 - 5.7.11 GHSA-q6wp-fr43-gm9v
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
3 hours ago
October 09, 2026 at 08:53 PM UTC
Fixed (5.7.12)
1 month ago
August 25, 2026 at 07:59 AM UTC
Last Modified
3 hours ago
October 09, 2026 at 09:00 PM UTC