CVE-2026-107851 Contao 权限绕过漏洞
影响低权限后台用户可越权读写未授权数据表
Contao CMS 的 TableAccessVoter::hasAccessToModule() 在缓存授权决策时仅使用用户安全令牌的哈希 $tokenHash,未包含 getDataSource() 返回的表名。当同一请求先检查允许访问的表、再检查被拒绝的表时,投票器会复用之前的允许结果,导致权限判断错误。该漏洞影响 5.7.0 至 5.7.12 之前的版本,已在 5.7.12 修复。
影响范围
Contao 5.7.0 至 5.7.12 之前的版本。
漏洞详情
漏洞类型为授权缓存键设计缺陷导致的权限绕过。TableAccessVoter 缓存授权结果时只以 $tokenHash 为键,遗漏了数据表名,使不同表的权限检查共享同一缓存条目;同时 DefaultDataContainerVoter 可能将错误的弃权转换为授权。低权限后台用户借此可读取、创建、更新或删除其模块权限之外的记录,包括成员或新闻订阅者数据表。
利用条件与风险
利用前提是攻击者拥有低权限后台账户,并能构造先访问允许表、再访问拒绝表的请求顺序。实战中可导致敏感数据泄露和未授权数据篡改,风险中等。
修复建议
官方已在 Contao 5.7.12 中修复,建议升级至该版本或更高版本。临时缓解措施暂无公开信息。
Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the user’s security token, and omits the table returned by getDataSource(). If one request first checks a table allowed to the user and then a different denied table, the voter can reuse the allowed result, while DefaultDataContainerVoter can convert an incorrect abstention into a grant. A low-privileged backend user can consequently read, create, update, or delete records in tables outside assigned module permissions, including tables containing member or newsletter-subscriber data. This issue is fixed in version 5.7.12.