SCA: security update for contao/core-bundle (GHSA-x2rp-9qf7-2fmq)

medium Tenable Self-Hosted Container Security Plugin ID 474061

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, ModuleSearch can disclose
protected page titles, URLs, and indexed context snippets to unauthenticated visitors when
contao.search.index_protected is changed from enabled to disabled. Authorization metadata is stored per
row in tl_search, but disabling the setting removes the protected-row filter without deleting rows indexed
while protection was enabled. The protected pages continue to return an authorization response, so this
issue exposes search metadata and indexed text rather than bypassing page access. This issue is fixed in
versions 5.3.50 and 5.7.12. (CVE-2026-107842)

Solution

Update the contao/core-bundle library and its related packages to version 5.3.50 or later.

See Also

https://github.com/advisories/GHSA-x2rp-9qf7-2fmq

Plugin Details

Severity: Medium

ID: 474061

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/10/2026

Updated: 10/10/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2026-107842

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/9/2026

Vulnerability Publication Date: 10/9/2026

Reference Information

CVE: CVE-2026-107842

cwe: CWE-200