by Leo Feyer

Unrestricted activation email resending

Date: 2026-08-25
CVE ID: CVE-2026-XXXXX

Description

If a website has a registration module, anyone can register arbitrary email addresses and trigger the activation email to be resent indefinitely.

Affected versions

Contao 4.1
Contao 4.2
Contao 4.3
Contao 4.4
Contao 4.5
Contao 4.6
Contao 4.7
Contao 4.8
Contao 4.9
Contao 4.10
Contao 4.11
Contao 4.12
Contao 4.13
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11

Suggested solution

Upgrade to Contao 5.3.50 or 5.7.12.

Workaround

Disable the member registration in the frontend.

More information

https://github.com/contao/contao/security/advisories/GHSA-mfxh-vp55-7gc6