ModuleSearch decides whether to filter protected pages out of search results based on the current value of contao.search.index_protected, but the authorisation data lives per row in tl_search. Turning the setting off removes
the filter without removing the rows, so protected pages that were indexed while it was on are returned to unauthenticated visitors such as title, URL and context snippet, even though the pages themselves still answer 401.
Disclosure of member-only page titles, URLs and indexed text to unauthenticated visitors through the site search. The pages themselves remain access-controlled, so this is not a page-access bypass.
This security vulnerability was found by @iRevivalx .
{
"cwe_ids": [
"CWE-200"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-09T20:54:09Z",
"nvd_published_at": null,
"severity": "MODERATE"
}