by Leo Feyer
Exposure of sensitive information through a stale search index
Date: 2026-08-25
CVE ID: CVE-2026-XXXXX
Description
If the frontend search index is not cleared after disabling indexing of protected pages, protected results remain visible to everyone.
Affected versions
Contao 4.0
Contao 4.1
Contao 4.2
Contao 4.3
Contao 4.4
Contao 4.5
Contao 4.6
Contao 4.7
Contao 4.8
Contao 4.9
Contao 4.10
Contao 4.11
Contao 4.12
Contao 4.13
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11
Suggested solution
Upgrade to Contao 5.3.50 or 5.7.12.
Workaround
Clear the search index after disabling indexing of protected pages.
More information
https://github.com/contao/contao/security/advisories/GHSA-x2rp-9qf7-2fmq