CVE-2026-107843: Contao: The registration module re-sends activation mails on any unauthenticated POST, with no throttle and no captcha check
ModuleRegistration::compile() reaches its follow-up registration branch on any POST to a page carrying the module. That branch checks neither FORMSUBMIT nor the captcha result computed immediately above it, and resendActivationMail() leads to OptInToken::send(), which has no rate limit at all.
Impact
Anyone on the internet can make a Contao installation send unlimited mail to an address of their choosing, from the site's own sender and reputation, at one outbound message per HTTP request. That is both a nuisance for the recipient and a deliverability risk for the site operator. The same request is a reliable account oracle for "this address has a pending registration on this site", which is exactly the sort of membership fact a public site is usually expected not to disclose.
Honest bound. The target must have an unconfirmed registration, that is tlmember.disable = 1 together with an unconfirmed reg- opt-in token. An attacker can create that state for an arbitrary address, since registration requires no ownership proof, but on a site where regactivate is off the branch is unreachable.
Other sources
Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORMSUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when regactivate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 5.7.12 - Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 5.3.50 - Upgrade
Upgrade
Contaoto a version that resolves this vulnerability.Fixed in 5.3.50 - Upgrade
Upgrade
Contaoto a version that resolves this vulnerability.Fixed in 5.7.12
Event History
Frequently Asked Questions
Which deployments are exposed to repeated activation-email sends?
A page must contain the registration module with reg_activate enabled. The targeted email address must have an unconfirmed registration and an associated opt-in token; confirmed registrations are not described as reachable through this branch.
What does an attacker need to exploit this?
No authentication, user interaction, captcha completion, or valid FORM_SUBMIT value is required. An attacker can send POST requests to a page containing the registration module to trigger the follow-up registration branch.
What is the practical impact?
An attacker can repeatedly cause activation emails to be sent to an address with a pending registration because the resend operation has no rate limiting. The behavior can also reveal whether a pending registration exists for a target address.
Which versions contain the fix?
The issue is fixed in Contao 5.3.50 and 5.7.12. The affected range is stated as versions from 4.1.0 until those fixed releases.