CVE-2026-107842: CVE-2026-107842: Information Disclosure via Stale Indexing in Contao Search Module
CVE-2026-107842: Information Disclosure via Stale Indexing in Contao Search Module Vulnerability ID: CVE-2026-107842 CVSS Score: 5.3 Published: 2026-10-09 An information disclosure vulnerability in Contao CMS allows
CVE-2026-107842: Information Disclosure via Stale Indexing in Contao Search Module
Vulnerability ID: CVE-2026-107842
CVSS Score: 5.3
Published: 2026-10-09
An information disclosure vulnerability in Contao CMS allows unauthenticated site visitors to view protected page titles, URLs, and text excerpts through search queries when protected page indexing is disabled after previously being enabled.
TL;DR
Contao's ModuleSearch failed to filter out stale protected page index entries from database table tl_search when contao.search.index_protected configuration was set to false, resulting in sensitive content disclosure in search results.
Technical Details
- CWE ID: CWE-200
- Attack Vector: Network (AV:N)
- CVSS v3.1 Score: 5.3 (Medium)
- EPSS Score: 0.00262 (16.62th percentile)
- Impact: Partial Information Disclosure
- Exploit Status: Unproven / No Public Exploits
- CISA KEV Status: Not Listed
Affected Systems
- Contao CMS 4.0.0 before 5.3.50
- Contao CMS 5.4.0-RC1 before 5.7.12
-
contao/contao: >= 4.0.0, < 5.3.50 (Fixed in:
5.3.50) -
contao/contao: >= 5.4.0-RC1, < 5.7.12 (Fixed in:
5.7.12)
Code Analysis
Commit: 572686a
Fix filtering of protected search results when index_protected is false
Mitigation Strategies
- Upgrade contao/contao package to patched version 5.3.50 or 5.7.12.
- Rebuild and purge the search index via the Contao Maintenance backend panel if index_protected configuration was modified.
Remediation Steps:
- Run 'composer update contao/contao --with-dependencies' in project root.
- Log in to Contao Backend and open the Maintenance module.
- Purge the Search Index database table tl_search.
- Rebuild search index to ensure only current public pages are indexed.
References
- GitHub Security Advisory GHSA-x2rp-9qf7-2fmq
- Contao Patch Commit 572686a113bca60f92cf2d0496cf3a74d0b6b457
- Contao Release Tag 5.3.50
- Contao Release Tag 5.7.12
- NVD Detail CVE-2026-107842
- CVE Record CVE-2026-107842
Read the full report for CVE-2026-107842 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.