CVE-2026-107850 | Contao up to 5.7.11 Preview Access Voter services.yaml PreviewVoter::hasAccess permission

SecurityVulns

A vulnerability classified as problematic was found in Contao up to 5.7.11. Affected by this issue is the function PreviewVoter::hasAccess of the file core-bundle/config/services.yaml of the component Preview Access Voter. The manipulation results in permission issues.

This vulnerability is known as CVE-2026-107850. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More