Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 1 min read

CVE-2026-107842: CVE-2026-107842: Information Disclosure via Stale Indexing in Contao Search Module

CVE-2026-107842: Information Disclosure via Stale Indexing in Contao Search Module Vulnerability ID: CVE-2026-107842 CVSS Score: 5.3 Published: 2026-10-09 An information disclosure vulnerability in Contao CMS allows

CVE-2026-107842: Information Disclosure via Stale Indexing in Contao Search Module

Vulnerability ID: CVE-2026-107842
CVSS Score: 5.3
Published: 2026-10-09

An information disclosure vulnerability in Contao CMS allows unauthenticated site visitors to view protected page titles, URLs, and text excerpts through search queries when protected page indexing is disabled after previously being enabled.

TL;DR

Contao's ModuleSearch failed to filter out stale protected page index entries from database table tl_search when contao.search.index_protected configuration was set to false, resulting in sensitive content disclosure in search results.

Technical Details

  • CWE ID: CWE-200
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 Score: 5.3 (Medium)
  • EPSS Score: 0.00262 (16.62th percentile)
  • Impact: Partial Information Disclosure
  • Exploit Status: Unproven / No Public Exploits
  • CISA KEV Status: Not Listed

Affected Systems

  • Contao CMS 4.0.0 before 5.3.50
  • Contao CMS 5.4.0-RC1 before 5.7.12
  • contao/contao: >= 4.0.0, < 5.3.50 (Fixed in: 5.3.50)
  • contao/contao: >= 5.4.0-RC1, < 5.7.12 (Fixed in: 5.7.12)

Code Analysis

Commit: 572686a

Fix filtering of protected search results when index_protected is false

Mitigation Strategies

  • Upgrade contao/contao package to patched version 5.3.50 or 5.7.12.
  • Rebuild and purge the search index via the Contao Maintenance backend panel if index_protected configuration was modified.

Remediation Steps:

  1. Run 'composer update contao/contao --with-dependencies' in project root.
  2. Log in to Contao Backend and open the Maintenance module.
  3. Purge the Search Index database table tl_search.
  4. Rebuild search index to ensure only current public pages are indexed.

References

Read the full report for CVE-2026-107842 on our website for more details including interactive diagrams and full exploit analysis.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.