CVE-2026-107850 Contao 预览链接权限绕过漏洞
影响非管理员用户可越权查看未发布页面
Contao 是一款开源 CMS。在 5.7.1 至 5.7.12 版本中,core-bundle/config/services.yaml 将预览访问投票器注册为 PreviewAccessVoter,而实际类名为 PreviewVoter,导致 Symfony 未自动配置该投票器并移除私有服务,权限校验失效。
影响范围
Contao 5.7.1 至 5.7.12 版本受影响,5.7.12 已修复。
漏洞详情
由于服务配置中的类名与实际类名不一致,Symfony 无法自动装配该投票器,导致 PreviewVoter::hasAccess() 从未执行所有权校验。拥有 preview_link 模块的非管理员后台用户可列出所有 tl_preview_link 记录,获取其他用户创建的签名分享链接,从而在无页面权限的情况下查看未发布页面。
利用条件与风险
利用需具备后台账户及 preview_link 模块权限,属于越权信息泄露,暂未发现可编辑或删除他人链接。
修复建议
升级至 Contao 5.7.12 或更高版本;临时可修正 services.yaml 中的类名或限制 preview_link 模块权限。
Contao is an Open Source CMS. From version 5.7.1 until 5.7.12, core-bundle/config/services.yaml registers the preview access voter as ContaoCoreBundleSecurityVoterDataContainerPreviewAccessVoter although the shipped class is PreviewVoter. Symfony therefore omits voter autoconfiguration and removes the private service, so PreviewVoter::hasAccess() never enforces ownership. A non-admin backend user with the preview_link module can list every tl_preview_link record, obtain signed share URLs created by other users, and use them to view unpublished pages with showUnpublished despite lacking page permission. The advisory does not establish editing or deletion of foreign links. This issue is fixed in version 5.7.12.