Code Injection Vulnerability in SPIP by SPIP Team
CVE-2026-66738

7.7HIGH

Key Information:

Vendor

Spip

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-66738?

A critical code injection vulnerability exists in SPIP versions prior to 4.4.18, specifically in installations using SQLite. The issue arises in the navigation menu endpoint, where the system fails to properly sanitize array-typed user input. This flaw allows an authenticated attacker, possessing at least editor-level privileges, to craft and submit a GET request that executes arbitrary OS commands on the web server. Notably, installations backed by MySQL are not impacted by this vulnerability. Proper patching and adherence to security best practices are crucial to mitigate potential threats.

Affected Version(s)

SPIP 0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Benoit Hua of Fenrisk (www.fenrisk.com)
VulnCheck
.