Contao, Authentication Bypass, CVE-2025-57758 (Critical) -DC-Oct2026-3047

Listen to this Post

Due to a caching defect in Contao’s security voter that governs table-level access to the Data Container backend, a low-privileged user can gain unauthorized read, create, update, and delete access.
The backend organizes permissions by modules assigned to user groups, determining allowed database tables.
Contao checks if a user’s group includes a table before granting access.
To optimize performance, Contao caches this check for the duration of the HTTP request.
However, the cache key is built solely from the user’s security token and lacks the specific table name.
Consequently, if a request first checks a permitted table, that positive authorization result is improperly cached and reused for subsequent table checks.
When a restricted table is checked next, the stale cache returns true instead of evaluating the table-specific permissions.
This caching flaw combines with DefaultDataContainerVoter, a permissive fallback voter granting access unless explicitly denied.
Because the stale cache returns no opinion, the fallback grants full access to unauthorized tables.
Most database tables lack secondary explicit checks, exposing sensitive records like member data and newsletter recipient emails.
Attackers with low privileges can exploit this to interact with restricted data container tables outside their assigned scopes.

DailyCVE Form:

Platform: Contao CMS
Version: 5.0.0 through 5.3.37
Vulnerability: Authentication Bypass
Severity: Critical
date: September 15 2026

Prediction: Released in 5.3.38

What Undercode Say:

The vulnerability stems from improper cache key generation in Symfony security voters where the target resource or table name is omitted from the cache hash.

composer req contao/core-bundle:^5.3.38
grep -rn "TableAccessVoter" vendor/contao/core-bundle/src/Security/Voter/DataContainer/
private array $canAccessTable = [];
private function hasAccessToModule(TokenInterface $token, ...): bool {
$tokenHash = hash('xxh128', serialize($token));
if (isset($this->canAccessTable[$tokenHash])) {
return $this->canAccessTable[$tokenHash];
}
}

Exploit: (Educational Purposes!)

An authenticated low-privileged backend user sends an HTTP request targeting a permitted module/table first, followed by a request to a restricted table like `tl_member` or `tl_newsletter_recipients` within the same request lifecycle to trigger the stale cache reuse.

Protection: from this CVE

Upgrade Contao core bundle to version 5.3.38 or 5.6.1, where the TableAccessVoter implementation correctly includes table scope in permission validation and removes direct voter interface inheritance flaws.

Impact:

Allows authenticated low-privileged backend users to completely bypass module-level access controls, obtaining unauthorized read, write, update, and delete privileges on sensitive database tables containing personal user data and subscriber details.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top