Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-72710: SPIP lets attackers run code via job queue
CVE-2026-72710 · published 28 days ago
Summary
The SPIP publishing system (including Debian and Ubuntu packages) lets anyone on the internet add their own entries to the internal job list. When the system’s scheduled task processes that list, it will execute the attacker’s code, potentially taking complete control of the server. Update SPIP to version 4.4.18 or later, or apply the vendor’s patch, to stop this behavior.
What to do
- Update debian spip to version 4.4.19+dfsg-0+deb13u1.
- Update debian spip to version 4.4.18+dfsg-1.
- Update spip spip to version 4.4.18 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | spip | spip | < 4.4.18 |
| Debian:13 | debian | spip |
< 4.4.19+dfsg-0+deb13u1 Fix: upgrade to 4.4.19+dfsg-0+deb13u1
|
| Debian:14 | debian | spip |
< 4.4.18+dfsg-1 Fix: upgrade to 4.4.18+dfsg-1
|
| Ubuntu:Pro:16.04:LTS | canonical | spip | All versions |
Original advisory text
SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection
SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter resolving to internal database tables. Attackers can insert a malicious row into the spip_jobs queue with a controlled PHP function and arguments, which is then dynamically executed when the cron processes the queue, resulting in remote code execution.
References
- https://blog.lexfo.fr/casse-spip-sqli-to-rce.html
- https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.htm...
- https://security-tracker.debian.org/tracker/CVE-2026-72710 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-72710 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-72710 Third Party Advisory
- https://www.vulncheck.com/advisories/spip-remote-code-execution-via-editer-objet...
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes
Timeline
Published11 Sep 2026
Updated9 Oct 2026
First seen11 Sep 2026
Sources
CVE-2026-72710 · NVD
CVE-2026-72710 · MITRE
DEBIAN-CVE-2026-72710 · OSV
UBUNTU-CVE-2026-72710 · OSV
Track software like this
Free during beta