Remote Code Execution Vulnerability in SPIP by SPIP Team
CVE-2026-77806
9.8CRITICAL
What is CVE-2026-77806?
Prior to version 4.4.21, SPIP is susceptible to a critical remote code execution vulnerability. Unauthenticated attackers can exploit this weakness by sending specially crafted HTTP requests containing the X-Spip-Filtre header. This improperly handled data can lead to arbitrary code execution, putting affected systems at risk. Prompt updates to the latest version are essential to mitigate potential exploitation.
Affected Version(s)
SPIP 0 < 4.4.21
