by Leo Feyer
Improper access control in the preview links module
Date: 2026-08-25
CVE ID: CVE-2026-XXXXX
Description
A backend user can edit preview links that they do not have permission to access.
Affected versions
Contao 5.7.1 up to 5.7.11
Suggested solution
Upgrade to Contao 5.7.12.
Workaround
Revoke access to the preview links module.
More information
https://github.com/contao/contao/security/advisories/GHSA-q6wp-fr43-gm9v