{"id":"CVE-2026-107848","summary":"Contao: Cross-site request forgery in custom backend actions","details":"Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12.","aliases":["GHSA-9ff2-p842-45wq"],"modified":"2026-10-10T10:45:14.904835004Z","published":"2026-10-09T20:22:12.778Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-352"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107848.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107848.json"},{"type":"FIX","url":"https://github.com/contao/contao/commit/34dd27ee6739f10568d3d95d8784862255c925b4"},{"type":"WEB","url":"https://github.com/contao/contao/releases/tag/5.7.12"},{"type":"ADVISORY","url":"https://github.com/contao/contao/security/advisories/GHSA-9ff2-p842-45wq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107848"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/contao/contao","events":[{"introduced":"84b2fe637d5ead531f117f26b48d1b9de8df4074"},{"fixed":"a11109b60dedcbd99e32a4e8550afdadb500f2c5"},{"introduced":"c5e3841e5107ab36ae2bf7795fb8d51d3d30f88b"},{"fixed":"a6543f49a92187a7368f51b290179c4795386e23"}],"database_specific":{"extracted_events":[{"introduced":"4.0.0"},{"fixed":"5.3.50"},{"introduced":"5.4.0-RC1"},{"fixed":"5.7.12"}],"source":"AFFECTED_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107848.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}