CVE-2026-107850: Contao: Improper access control in the preview links module
core-bundle/config/services.yaml registers the preview access voter with the class Contao\CoreBundle\Security\Voter\DataContainer\PreviewAccessVoter, but the class shipped on disk is named PreviewVoter. Symfony resolves the class with getReflectionClass($class, false), gets null, silently skips the interface based autoconfiguration that would have tagged it as a voter, and the now untagged private service is removed when the container is compiled. The application boots without a warning, and the ownership rule in PreviewVoter::hasAccess() is never executed. tlpreviewlink has no compensating SQL filter on createdBy, so any non administrator back end user whose group holds the previewlink module reads every preview link on the installation and lifts the already signed share URLs straight out of the list. Following one grants front end preview of the target page, with showUnpublished and with no page permission check, to anyone at all.
Impact
A non administrator back end user reads every preview link on the installation, including links created by administrators, and lifts the already signed share URLs out of the list. Following one grants front end preview of the target page with showUnpublished and with no page permission check at all, so unpublished or embargoed content becomes readable by a user who has no rights on those pages, and by anyone that user forwards the URL to.
Honesty caveat, stated because it bounds the severity. UpdateAction on a record owned by someone else was denied in our lab by DcaPermissionVoter, so we do not claim that a foreign preview link can be edited or deleted.
Other sources
Contao is an Open Source CMS. From version 5.7.1 until 5.7.12, core-bundle/config/services.yaml registers the preview access voter as Contao\CoreBundle\Security\Voter\DataContainer\PreviewAccessVoter although the shipped class is PreviewVoter. Symfony therefore omits voter autoconfiguration and removes the private service, so PreviewVoter::hasAccess() never enforces ownership. A non-admin backend user with the previewlink module can list every tlpreviewlink record, obtain signed share URLs created by other users, and use them to view unpublished pages with showUnpublished despite lacking page permission. The advisory does not establish editing or deletion of foreign links. This issue is fixed in version 5.7.12.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 5.7.12 - Upgrade
Upgrade
Contaoto a version that resolves this vulnerability.Fixed in 5.7.12
Event History
Frequently Asked Questions
Who can exploit this issue?
A non-admin backend user who has access to the preview_link module can exploit it. The issue affects Contao versions from 5.7.1 through 5.7.12 as described in the advisory.
What information can an attacker obtain and use?
An affected backend user can list all tl_preview_link records, including signed share URLs created by other users. Those URLs can be used to view unpublished pages with showUnpublished even when the user lacks permission for the relevant pages.
Does this allow modification or deletion of other users' preview links?
The advisory does not establish that foreign preview links can be edited or deleted. The documented impact is unauthorized listing of preview-link records and use of their signed share URLs.
What is the remediation?
Update Contao to version 5.7.12, which fixes the issue. Until updating, restrict access to the preview_link module to trusted administrators and users who should be able to access all preview links.