Remote Code Execution Vulnerability in SPIP by SPIP Team
CVE-2026-77806
What is CVE-2026-77806?
CVE-2026-77806 is a remote code execution vulnerability found in SPIP, an open-source content management system (CMS) designed primarily for managing and publishing web content. This vulnerability exists in versions prior to 4.4.21 and allows unauthenticated remote attackers to exploit a flaw related to code injection through the mishandling of the X-Spip-Filtre HTTP request header in the analyse_resultat_skel function. If successfully exploited, an attacker could execute arbitrary code on the affected SPIP installations, leading to potentially severe disruptions for organizations using this CMS. The implications of such unauthorized code execution are vast, impacting both the integrity and availability of organizational data and services.
Potential impact of CVE-2026-77806
-
Unauthorized Access and Control: The vulnerability allows attackers to execute arbitrary code, potentially gaining full control over compromised systems. This unauthorized access can lead to data manipulation, theft, or destruction of sensitive information.
-
Service Disruption: Successful exploitation may result in significant service degradation or complete outages of web applications managed by SPIP, impacting user access and organizational operations.
-
Increased Attack Surface: With the possibility of remote code execution, compromised systems can be used as launching pads for further attacks within the network, leading to cascading vulnerabilities and broader security breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SPIP 0 < 4.4.21
