by Leo Feyer

Improper access control in the newsletter module

Date: 2026-08-25
CVE ID: CVE-2026-XXXXX

Description

A backend user can edit recipients and send newsletters for channels they do not have permission to access.

Affected versions

Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11

Suggested solution

Upgrade to Contao 5.3.50 or 5.7.12.

Workaround

Revoke access to the newsletter module for regular backend users.

More information

https://github.com/contao/contao/security/advisories/GHSA-3r9g-pfhv-3228