by Leo Feyer

Improper access control in the CSV import wizard

Date: 2026-08-25
CVE ID: CVE-2026-XXXXX

Description

A regular backend user can import CSV data into arbitrary content elements and form fields that they do not have permission to access.

Affected versions

Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11

Suggested solution

Upgrade to Contao 5.3.50 or 5.7.12.

More information

https://github.com/contao/contao/security/advisories/GHSA-23w9-4pg3-xwm3