Insecure Deserialization Vulnerability in SPIP by SPIP Team
CVE-2026-27475

9.2CRITICAL

Key Information:

Vendor

Spip

Status
Vendor
CVE Published:
19 February 2026

What is CVE-2026-27475?

Prior to version 4.4.9, SPIP is susceptible to an Insecure Deserialization vulnerability. This issue arises through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker, assuming they can provide malicious serialized content due to prior access or exploitation of another vulnerability, may trigger arbitrary object instantiation. This could lead to code execution. The use of serialized data in these components is deprecated, with plans for removal in SPIP 5. Furthermore, this vulnerability is not mitigated by the existing SPIP security screen.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SPIP 4.4.0 < 4.4.9

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dorian Piette (Trachinus)
.