CVE-2026-107848: Cross-Site Request Forgery (CSRF) in Contao Backend Actions via GET Requests
Vulnerability ID: CVE-2026-107848
CVSS Score: 3.5
Published: 2026-10-09
Contao Open Source CMS versions 4.0.0 through 5.3.49 and 5.4.0-RC1 through 5.7.11 contain a Cross-Site Request Forgery (CSRF) vulnerability in backend parameter handling. The RequestTokenListener component validates anti-CSRF tokens solely for HTTP POST requests, while GET-based declarative guards run only when an act parameter is present in the query string. Consequently, custom backend actions dispatched via alternative parameters such as key= can execute without CSRF token verification when triggered by an authenticated user.
TL;DR
Contao CMS fails to validate anti-CSRF tokens for custom backend GET actions using query parameters like key=. An attacker can trick an authenticated backend user into visiting a crafted URL to execute unauthorized state-changing operations within the user's permission scope.
Technical Details
- CWE ID: CWE-352 (Cross-Site Request Forgery)
- Attack Vector: Network (AV:N)
- CVSS v3.1 Score: 3.5 (Low)
- EPSS Score: 0.00113 (1.34th percentile)
- Impact: Low Integrity Impact (State-changing backend operations)
- Exploit Status: None / No public functional exploit
- CISA KEV Status: Not listed
Affected Systems
- Contao Open Source CMS (contao/contao) >= 4.0.0, < 5.3.50
- Contao Open Source CMS (contao/contao) >= 5.4.0-RC1, < 5.7.12
-
contao/contao: >= 4.0.0, < 5.3.50 (Fixed in:
5.3.50) -
contao/contao: >= 5.4.0-RC1, < 5.7.12 (Fixed in:
5.7.12)
Code Analysis
Commit: 34dd27e
Enforce POST method and explicit CSRF token checks for custom key backend operations
Mitigation Strategies
- Upgrade Contao CMS to version 5.3.50, 5.7.12, or higher.
- Enforce HTTP POST method on all custom state-changing DCA actions (
key=). - Implement explicit
ContaoCsrfTokenManager::isTokenValid()verification in custom controller handlers. - Configure backend session cookies with
SameSite=StrictorSameSite=Laxattributes.
Remediation Steps:
- Run
php composer.phar update contao/contaoto pull the latest security fixes. - Audit custom third-party extensions for GET-based backend actions using
key=query parameters. - Update custom DCA definitions to require
'method' => 'POST'for state-changing operations. - Clear application cache and verify backend operation behavior.
References
- GitHub Security Advisory GHSA-9ff2-p842-45wq
- Patch Commit 34dd27ee6739f10568d3d95d8784862255c925b4
- Contao v5.7.12 Release Notes
- NVD CVE-2026-107848 Detail
Read the full report for CVE-2026-107848 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)