by Leo Feyer
Unrestricted activation email resending
Date: 2026-08-25
CVE ID: CVE-2026-XXXXX
Description
If a website has a registration module, anyone can register arbitrary email addresses and trigger the activation email to be resent indefinitely.
Affected versions
Contao 4.1
Contao 4.2
Contao 4.3
Contao 4.4
Contao 4.5
Contao 4.6
Contao 4.7
Contao 4.8
Contao 4.9
Contao 4.10
Contao 4.11
Contao 4.12
Contao 4.13
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11
Suggested solution
Upgrade to Contao 5.3.50 or 5.7.12.
Workaround
Disable the member registration in the frontend.
More information
https://github.com/contao/contao/security/advisories/GHSA-mfxh-vp55-7gc6