Core bundle: Contao: Protected page content is disclosed to anonymous visitors after contao.search.index_protected is disabled (CVE-2026-107842)
Description
A vulnerability in Contao core bundle allows disclosure of protected page titles, URLs, and indexed text to unauthenticated visitors via site search when the setting contao.search.index_protected is disabled. The pages themselves remain access-controlled and do not allow unauthorized access. This issue affects versions from 4.0.0 up to but not including 5.3.50 and from 5.4.0-RC1 up to but not including 5.7.12. A patch is available to address this information disclosure.
CVSS v3.1
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because the ModuleSearch component filters protected pages from search results based on the contao.search.index_protected setting, but the authorization data is stored per row in the tl_search table. Disabling the setting removes the filter but does not remove the indexed rows, causing protected pages indexed while the setting was enabled to be returned in search results to unauthenticated users. This leads to disclosure of member-only page titles, URLs, and indexed text snippets, although the pages themselves still enforce access control (401 responses).
Potential Impact
This vulnerability results in information disclosure of protected page metadata (titles, URLs, and indexed text) to unauthenticated visitors through the site search feature. It does not allow unauthorized access to the actual page content, which remains protected by access controls.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade to versions later than 5.3.50 or later than 5.7.12 where the issue is fixed. Until patched, avoid disabling the contao.search.index_protected setting to prevent disclosure of protected page information.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-x2rp-9qf7-2fmq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-107842"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ac96e432cdf04f65689a67e
Added to database: 10/09/2026, 22:44:19 UTC
Last enriched: 10/09/2026, 22:46:31 UTC
Last updated: 10/09/2026, 22:46:31 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.