Remote Code Execution in SPIP by SPIP
CVE-2026-72710
9.3CRITICAL
What is CVE-2026-72710?
SPIP versions prior to 4.4.18 are susceptible to a remote code execution vulnerability through the editer_objet action. This issue arises when the arg parameter resolves SQL table names without enforcing an editable columns allowlist, enabling attackers with a valid nonce to inject malicious rows into the spip_jobs table. By manipulating the arg=job/0 with crafted function and arguments, attackers can leverage this vulnerability to trigger arbitrary PHP function execution on the server when the cron job queue is processed. This presents a significant risk to the integrity and security of the affected systems.
Affected Version(s)
SPIP 0 < 4.4.18
