CVE-2026-107848 | Contao up to 5.3.49/5.7.11 Request Token Validation RequestTokenListener act/key cross-site request forgery

SecurityVulns

A vulnerability, which was classified as problematic, has been found in Contao up to 5.3.49/5.7.11. This affects the function RequestTokenListener of the component Request Token Validation. This manipulation of the argument act/key causes cross-site request forgery.

This vulnerability is handled as CVE-2026-107848. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More