Privilege Escalation in SPIP by SPIP Team
CVE-2026-33549

6.7MEDIUM

Key Information:

Vendor

Spip

Status
Vendor
CVE Published:
22 March 2026

What is CVE-2026-33549?

A vulnerability exists in SPIP versions 4.4.10 to 4.4.12 that allows for the unintended assignment of administrator privileges when editing an author's data structure. This occurs due to improper handling of the STATUT attribute, potentially granting elevated access rights to unauthorized users. It is crucial for users of affected versions to upgrade to version 4.4.13 or later to mitigate the risk of exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SPIP 4.4.10 < 4.4.13

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.