Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-72709: SPIP lets attackers change passwords without permission

CVE-2026-72709 · published 28 days ago
Summary

Versions of SPIP older than 4.4.18 let anyone send a specially crafted request to change user passwords, even for administrator accounts, without proper permission checks. This can lead to full account takeover. Upgrade SPIP to version 4.4.18 or later to close the gap.

What to do
  • Update debian spip to version 4.4.19+dfsg-0+deb13u1.
  • Update debian spip to version 4.4.18+dfsg-1.
  • Update spip spip to version 4.4.18 or later.
Affected software
Ecosystem VendorProductAffected versions
– spip spip < 4.4.18
Ubuntu:Pro:16.04:LTS canonical spip All versions
Debian:13 debian spip < 4.4.19+dfsg-0+deb13u1
Fix: upgrade to 4.4.19+dfsg-0+deb13u1
Debian:14 debian spip < 4.4.18+dfsg-1
Fix: upgrade to 4.4.18+dfsg-1
Original advisory text
SPIP < 4.4.18 Missing Authorization via ecrire/action/
SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can bypass template-level authorization guards through direct HTTP requests to invoke actions such as editer_auteur, enabling arbitrary account password rewrites including administrator accounts and resulting in full account takeover.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-862Missing Authorization
Timeline
Published11 Sep 2026
Updated9 Oct 2026
First seen11 Sep 2026
Track software like this
Free during beta