by Leo Feyer

Improper access control in the preview links module

Date: 2026-08-25
CVE ID: CVE-2026-XXXXX

Description

A backend user can edit preview links that they do not have permission to access.

Affected versions

Contao 5.7.1 up to 5.7.11

Suggested solution

Upgrade to Contao 5.7.12.

Workaround

Revoke access to the preview links module.

More information

https://github.com/contao/contao/security/advisories/GHSA-q6wp-fr43-gm9v