Privilege Escalation in SPIP by SPIP Team
CVE-2026-33549
6.7MEDIUM
What is CVE-2026-33549?
A vulnerability exists in SPIP versions 4.4.10 to 4.4.12 that allows for the unintended assignment of administrator privileges when editing an author's data structure. This occurs due to improper handling of the STATUT attribute, potentially granting elevated access rights to unauthorized users. It is crucial for users of affected versions to upgrade to version 4.4.13 or later to mitigate the risk of exploitation.
Affected Version(s)
SPIP 4.4.10 < 4.4.13
