by Leo Feyer

Non-admin users can self-grant permissions that implicitly make them administrators

Date: 2026-08-25
CVE ID: CVE-2026-XXXXX

Description

Regular backend users with access to the users module can grant themselves permissions that implicitly make them administrators.

Affected versions

Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11

Suggested solution

Upgrade to Contao 5.3.50 or 5.7.12.

Workaround

Revoke access to the users and user groups modules for regular backend users.

More information

https://github.com/contao/contao/security/advisories/GHSA-r9qp-pqx5-8369