by Leo Feyer
Improper access control in the CSV import wizard
Date: 2026-08-25
CVE ID: CVE-2026-XXXXX
Description
A regular backend user can import CSV data into arbitrary content elements and form fields that they do not have permission to access.
Affected versions
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11
Suggested solution
Upgrade to Contao 5.3.50 or 5.7.12.
More information
https://github.com/contao/contao/security/advisories/GHSA-23w9-4pg3-xwm3