by Leo Feyer
Improper access control in the newsletter module
Date: 2026-08-25
CVE ID: CVE-2026-XXXXX
Description
A backend user can edit recipients and send newsletters for channels they do not have permission to access.
Affected versions
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11
Suggested solution
Upgrade to Contao 5.3.50 or 5.7.12.
Workaround
Revoke access to the newsletter module for regular backend users.
More information
https://github.com/contao/contao/security/advisories/GHSA-3r9g-pfhv-3228