Remote Code Execution Vulnerability in SPIP by SPIP Team
CVE-2026-8429

8.7HIGH

Key Information:

Vendor

Spip

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-8429?

Versions of SPIP earlier than 4.4.14 are vulnerable to a remote code execution exploit that can compromise the private space of the application. This flaw allows unauthorized attackers to execute arbitrary code within the web server context, effectively bypassing existing security measures. By leveraging this vulnerability, an attacker can gain significant control over the affected systems, highlighting the urgent need for updates and security patches to mitigate potential risks.

Affected Version(s)

SPIP 0 < 4.4.14

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Louka Jacques-Chevallier
.