CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-107843

CVE-2026-107843: Unthrottled Activation Email Resend and Account Enumeration in Contao CMS

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 10, 2026·4 min read·4 visits

Executive Summary (TL;DR)

Unauthenticated attackers can send repeated HTTP POST requests to Contao registration pages to trigger activation emails without captcha verification or rate limiting, causing mail flooding and unconfirmed account enumeration.

Contao CMS versions 4.1.0 through 5.3.49 and 5.4.0-RC1 through 5.7.11 fail to validate form submission tokens and enforce rate limiting when processing activation email resend requests via HTTP POST, enabling resource exhaustion and account state enumeration.

Vulnerability Overview

Contao Open Source Content Management System exposes an attack surface within its registration module handling logic (ModuleRegistration::compile()). When the activation setting reg_activate is enabled, the system handles follow-up account registration requests for users who have not yet confirmed their accounts via email.

The vulnerability allows unauthenticated remote attackers to submit HTTP POST requests targeting registration endpoints without verifying form submission tokens or completing captcha checks. This flaw compromises the application's resource management and anti-automation checks during registration workflows.

Classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-204 (Observable Response Discrepancy), this issue exposes endpoints to automated mail dispatch generation and membership state disclosure.

Root Cause Analysis

The root cause lies within ModuleRegistration::compile(), where conditional checks evaluated whether to execute follow-up registration actions. Specifically, the execution branch evaluated Input::post('email', true) and performed a lookup via MemberModel::findUnactivatedByEmail(), without checking whether the form was legitimately submitted or passed anti-automation validations.

In standard Contao form processing, form submissions set Input::post('FORM_SUBMIT') to match the internal form ID $strFormId. Furthermore, validation filters set the flag $doNotSubmit to true whenever captcha challenges fail or mandatory fields contain invalid formatting. In affected versions, ModuleRegistration::compile() evaluated the follow-up branch prior to or independently of these parameters.

When a matching unactivated user record was found, the code directly called resendActivationMail($objMember). Inside resendActivationMail(), the application instantiated OptInToken::send() without evaluating rate limit counters or tracking submission frequency, allowing unlimited invocation per IP or user ID.

Code Analysis & Patch Review

The vulnerability fix was committed to contao/contao under commit 2ea6117f9049db7221679251cfc41e67d941a74b. The fix modifies core-bundle/contao/modules/ModuleRegistration.php to enforce submission validation and introduces rate limiting via the Symfony service container.

// Vulnerable Condition:
if ($this->reg_activate && Input::post('email', true) && ($objMember = MemberModel::findUnactivatedByEmail(Input::post('email', true))) !== null)
 
// Patched Condition:
if (!$doNotSubmit && Input::post('FORM_SUBMIT') == $strFormId && $this->reg_activate && Input::post('email', true) && ($objMember = MemberModel::findUnactivatedByEmail(Input::post('email', true))) !== null)

The updated condition ensures that the follow-up logic executes only if $doNotSubmit is false and FORM_SUBMIT matches $strFormId. Additionally, the patch modifies resendActivationMail() to integrate the rate limiter:

$factory = System::getContainer()->get('contao.rate_limit.member_password_factory');
$limiter = $factory->create($objMember->id);
 
if (!$limiter->consume()->isAccepted())
{
    $this->Template->type = 'error';
    $this->Template->message = $GLOBALS['TL_LANG']['MSC']['tooManyResendActivationAttempts'];
    return;
}

Exploitation Dynamics & Attack Methodology

An unauthenticated attacker executes this vulnerability by transmitting automated HTTP POST requests directly to any page hosting a Contao registration module. The body of the request includes the email field containing a target email address.

Because the vulnerable function did not validate FORM_SUBMIT or captcha fields, anti-bot controls placed on the registration form are entirely bypassed. Each request triggers an outbound SMTP email containing a new opt-in token to the specified recipient address.

Furthermore, the application returns observable response discrepancies depending on whether the specified target email corresponds to a pending, unconfirmed account registration. An attacker can analyze response templates to harvest information on active pending registrations across the system.

Impact Assessment

The primary impact of CVE-2026-107843 consists of resource exhaustion and observable response discrepancies. The flaw allows external actors to flood victim email inboxes with repetitive activation notifications and consume host SMTP server resources.

The CVSS v3.1 score is evaluated at 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Confidentiality impact is Low due to the ability to disclose unconfirmed account registration states. Integrity and Availability impacts are rated None at the primary application layer, though downstream email server resources are subject to operational strain.

According to EPSS data, the exploit probability score is 0.00255 (15.79th percentile). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public active exploitation scripts have been reported.

Remediation & Mitigation Guidance

To remediate CVE-2026-107843, administrators must update Contao installations to the patched versions: Contao 5.3.50 for the 5.3 release train, or Contao 5.7.12 for the 5.7 release train.

If immediate software updates cannot be deployed, web application firewalls (WAF) or reverse proxies should be configured to rate limit incoming HTTP POST requests directed at registration module URLs containing the email field.

Monitoring logic should be implemented to identify anomalous clusters of HTTP POST requests targeting registration endpoints, specifically monitoring log patterns for repeated resend responses.

Official Patches

ContaoContao Security Advisory GHSA-mfxh-vp55-7gc6
ContaoFix Commit 2ea6117f9049db7221679251cfc41e67d941a74b

Fix Analysis (1)

Technical Appendix

CVSS Score
5.3/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Probability
0.26%
Top 84% most exploited

Affected Systems

Contao Open Source CMS versions 4.1.0 through 5.3.49Contao Open Source CMS versions 5.4.0-RC1 through 5.7.11

Affected Versions Detail

Product
Affected Versions
Fixed Version
Contao Open Source CMS
Contao
>= 4.1.0, < 5.3.505.3.50
Contao Open Source CMS
Contao
>= 5.4.0-RC1, < 5.7.125.7.12
AttributeDetail
CWE IDCWE-770, CWE-204
Attack VectorNetwork (Unauthenticated HTTP POST)
CVSS v3.15.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
EPSS Score0.00255 (15.79th percentile)
ImpactEmail Flooding / Account State Enumeration
Exploit StatusUnproven / No Public Exploit
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1499Endpoint Denial of Service
Impact
CWE-770
Allocation of Resources Without Limits or Throttling

The application allocates limited resources such as outbound email dispatch without imposing rate limits or checking form validation tokens.

Vulnerability Timeline

Fix commit pushed to contao/contao repository
2026-08-25
GitHub Security Advisory and CVE-2026-107843 Published
2026-10-09

References & Sources

  • [1]GitHub Security Advisory GHSA-mfxh-vp55-7gc6
  • [2]Contao Fix Commit
  • [3]Contao Release 5.3.50
  • [4]Contao Release 5.7.12
  • [5]NVD CVE-2026-107843 Detail
  • [6]CVE Program Record CVE-2026-107843

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•7 minutes ago•CVE-2026-107848
3.5

CVE-2026-107848: Cross-Site Request Forgery (CSRF) in Contao Backend Actions via GET Requests

Contao Open Source CMS versions 4.0.0 through 5.3.49 and 5.4.0-RC1 through 5.7.11 contain a Cross-Site Request Forgery (CSRF) vulnerability in backend parameter handling. The `RequestTokenListener` component validates anti-CSRF tokens solely for HTTP POST requests, while GET-based declarative guards run only when an `act` parameter is present in the query string. Consequently, custom backend actions dispatched via alternative parameters such as `key=` can execute without CSRF token verification when triggered by an authenticated user.

Amit Schendel
Amit Schendel
0 views•5 min read
•about 2 hours ago•CVE-2026-107842
5.3

CVE-2026-107842: Information Disclosure via Stale Indexing in Contao Search Module

An information disclosure vulnerability in Contao CMS allows unauthenticated site visitors to view protected page titles, URLs, and text excerpts through search queries when protected page indexing is disabled after previously being enabled.

Amit Schendel
Amit Schendel
7 views•4 min read
•about 3 hours ago•GHSA-G38J-7V97-X298
6.5

GHSA-G38J-7V97-X298: Missing Authorization Check in Vikunja CalDAV Task Relation Creation

In Vikunja prior to version 2.6.0, relation creation via the CalDAV endpoint fails to invoke the TaskRelation.CanCreate authorization check. This missing access control allows an authenticated user to establish unauthorized relationships and perform write operations against any task, provided its unique identifier (UID) is known.

Alon Barad
Alon Barad
8 views•5 min read
•about 4 hours ago•GHSA-3HC7-R24J-RPWC
6.8

GHSA-3hc7-r24j-rpwc: Cross-Project Task Disclosure via Subtask Expansion in Vikunja

A cross-project information disclosure vulnerability in Vikunja allows authenticated users with read access to one project to view private task details from unauthorized projects via subtask expansion parameters.

Alon Barad
Alon Barad
8 views•5 min read
•about 5 hours ago•GHSA-8WVG-R2J4-3737
4.3

GHSA-8wvg-r2j4-3737: Email Address Exposure in Vikunja Task Assignees API

An information disclosure vulnerability in Vikunja allows authenticated users with read access to a task to expose private email addresses of assigned users through the API task assignees endpoint due to an unmasked database query.

Amit Schendel
Amit Schendel
8 views•5 min read
•about 6 hours ago•GHSA-W2CH-4XGR-22WW
5.3

GHSA-W2CH-4XGR-22WW: Missing Authorization in Vikunja Task Relation Deletion

An authorization bypass vulnerability in Vikunja versions prior to v2.6.0 permits authenticated users to delete relationships between tasks across project boundaries without requiring read or write authorization for the target related task.

Alon Barad
Alon Barad
7 views•5 min read