You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Contao does not properly manage privileges for page and article fields
Moderate severity
GitHub Reviewed
Published
Aug 28, 2025
in
contao/contao
•
Updated Aug 28, 2025
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Learn more on MITRE.
Impact
Under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions.
Patches
Update to Contao 5.3.38 or 5.6.1.
Workarounds
None.
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
References