SCA: security update for contao/core-bundle (GHSA-5974-gfqc-wrcm)

medium Tenable Self-Hosted Container Security Plugin ID 474060

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in
core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using
only $tokenHash, a hash of the user's security token, and omits the table returned by getDataSource(). If
one request first checks a table allowed to the user and then a different denied table, the voter can
reuse the allowed result, while DefaultDataContainerVoter can convert an incorrect abstention into a
grant. A low-privileged backend user can consequently read, create, update, or delete records in tables
outside assigned module permissions, including tables containing member or newsletter-subscriber data.
This issue is fixed in version 5.7.12. (CVE-2026-107851)

Solution

Update the contao/core-bundle library and its related packages to version 5.7.12 or later.

See Also

https://github.com/advisories/GHSA-5974-gfqc-wrcm

Plugin Details

Severity: Medium

ID: 474060

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/10/2026

Updated: 10/10/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2026-107851

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/9/2026

Vulnerability Publication Date: 10/9/2026

Reference Information

CVE: CVE-2026-107851