Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contao
Contao contao |
|
| Vendors & Products |
Contao
Contao contao |
Fri, 09 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, ModuleSearch can disclose protected page titles, URLs, and indexed context snippets to unauthenticated visitors when contao.search.index_protected is changed from enabled to disabled. Authorization metadata is stored per row in tl_search, but disabling the setting removes the protected-row filter without deleting rows indexed while protection was enabled. The protected pages continue to return an authorization response, so this issue exposes search metadata and indexed text rather than bypassing page access. This issue is fixed in versions 5.3.50 and 5.7.12. | |
| Title | Contao: Protected page content is disclosed to anonymous visitors after contao.search.index_protected is disabled | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T19:02:30.677Z
Reserved: 2026-10-08T22:34:49.291Z
Link: CVE-2026-107842
No data.
Status : Received
Published: 2026-10-09T20:17:10.013
Modified: 2026-10-09T20:17:10.013
Link: CVE-2026-107842
No data.
OpenCVE Enrichment
Updated: 2026-10-09T20:30:11Z
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor