by Leo Feyer

Exposure of sensitive information through a stale search index

Date: 2026-08-25
CVE ID: CVE-2026-XXXXX

Description

If the frontend search index is not cleared after disabling indexing of protected pages, protected results remain visible to everyone.

Affected versions

Contao 4.0
Contao 4.1
Contao 4.2
Contao 4.3
Contao 4.4
Contao 4.5
Contao 4.6
Contao 4.7
Contao 4.8
Contao 4.9
Contao 4.10
Contao 4.11
Contao 4.12
Contao 4.13
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11

Suggested solution

Upgrade to Contao 5.3.50 or 5.7.12.

Workaround

Clear the search index after disabling indexing of protected pages.

More information

https://github.com/contao/contao/security/advisories/GHSA-x2rp-9qf7-2fmq