The table access voter in the back end doesn't check if a user is allowed to access the corresponding module.
Update to Contao 5.3.38 or 5.6.1.
Do not rely solely on the voter and additionally check USER_CAN_ACCESS_MODULE.
If you have any questions or comments about this advisory, open an issue in contao/contao.
{
"cwe_ids": [
"CWE-284"
],
"github_reviewed": true,
"github_reviewed_at": "2025-08-28T14:40:45Z",
"nvd_published_at": "2025-08-28T17:15:36Z",
"severity": "MODERATE"
}