Our takeCERT-Bund updated its advisory on an information disclosure flaw in Contao that a remote authenticated attacker can exploit. Update if you run it yourself.Cyber Resilience desk
Sources (1)
- cert_bund · cert_bund
What this means for you — Security leader:Update Contao to a version that includes the fix for this confirmed information disclosure vulnerability. A remote authenticated attacker can exploit it to leak data.
What this means for you — Lean IT orgs:If you run your own Contao website, update it now to the latest version. Most smaller teams using a hosted Contao service can ignore this one.
What this means for you — MSP:Check client environments running self-hosted Contao and apply the update; hosted instances are typically unaffected.
What this means for you — Researcher:CERT-Bund advisory WID-SEC-2026-2287 details a confirmed information disclosure flaw in Contao exploitable by a remote authenticated attacker.