by Leo Feyer
Non-admin users can self-grant permissions that implicitly make them administrators
Date: 2026-08-25
CVE ID: CVE-2026-XXXXX
Description
Regular backend users with access to the users module can grant themselves permissions that implicitly make them administrators.
Affected versions
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11
Suggested solution
Upgrade to Contao 5.3.50 or 5.7.12.
Workaround
Revoke access to the users and user groups modules for regular backend users.
More information
https://github.com/contao/contao/security/advisories/GHSA-r9qp-pqx5-8369