CVE-2026-107851 | Contao up to 5.7.11 TableAccessVoter TableAccessVoter.php hasAccessToModule tokenHash improper authorization

SecurityVulns

A vulnerability categorized as critical has been discovered in Contao up to 5.7.11. The affected element is the function TableAccessVoter::hasAccessToModule of the file core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php of the component TableAccessVoter. The manipulation of the argument tokenHash results in improper authorization.

This vulnerability is cataloged as CVE-2026-107851. The attack may be launched remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More