DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-107848: CVE-2026-107848: Cross-Site Request Forgery (CSRF) in Contao Backend Actions via GET Requests

CVE-2026-107848: Cross-Site Request Forgery (CSRF) in Contao Backend Actions via GET Requests

Vulnerability ID: CVE-2026-107848
CVSS Score: 3.5
Published: 2026-10-09

Contao Open Source CMS versions 4.0.0 through 5.3.49 and 5.4.0-RC1 through 5.7.11 contain a Cross-Site Request Forgery (CSRF) vulnerability in backend parameter handling. The RequestTokenListener component validates anti-CSRF tokens solely for HTTP POST requests, while GET-based declarative guards run only when an act parameter is present in the query string. Consequently, custom backend actions dispatched via alternative parameters such as key= can execute without CSRF token verification when triggered by an authenticated user.

TL;DR

Contao CMS fails to validate anti-CSRF tokens for custom backend GET actions using query parameters like key=. An attacker can trick an authenticated backend user into visiting a crafted URL to execute unauthorized state-changing operations within the user's permission scope.


Technical Details

  • CWE ID: CWE-352 (Cross-Site Request Forgery)
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 Score: 3.5 (Low)
  • EPSS Score: 0.00113 (1.34th percentile)
  • Impact: Low Integrity Impact (State-changing backend operations)
  • Exploit Status: None / No public functional exploit
  • CISA KEV Status: Not listed

Affected Systems

  • Contao Open Source CMS (contao/contao) >= 4.0.0, < 5.3.50
  • Contao Open Source CMS (contao/contao) >= 5.4.0-RC1, < 5.7.12
  • contao/contao: >= 4.0.0, < 5.3.50 (Fixed in: 5.3.50)
  • contao/contao: >= 5.4.0-RC1, < 5.7.12 (Fixed in: 5.7.12)

Code Analysis

Commit: 34dd27e

Enforce POST method and explicit CSRF token checks for custom key backend operations

Mitigation Strategies

  • Upgrade Contao CMS to version 5.3.50, 5.7.12, or higher.
  • Enforce HTTP POST method on all custom state-changing DCA actions (key=).
  • Implement explicit ContaoCsrfTokenManager::isTokenValid() verification in custom controller handlers.
  • Configure backend session cookies with SameSite=Strict or SameSite=Lax attributes.

Remediation Steps:

  1. Run php composer.phar update contao/contao to pull the latest security fixes.
  2. Audit custom third-party extensions for GET-based backend actions using key= query parameters.
  3. Update custom DCA definitions to require 'method' => 'POST' for state-changing operations.
  4. Clear application cache and verify backend operation behavior.

References


Read the full report for CVE-2026-107848 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)