Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-72710: SPIP lets attackers run code via job queue

CVE-2026-72710 · published 28 days ago
Summary

The SPIP publishing system (including Debian and Ubuntu packages) lets anyone on the internet add their own entries to the internal job list. When the system’s scheduled task processes that list, it will execute the attacker’s code, potentially taking complete control of the server. Update SPIP to version 4.4.18 or later, or apply the vendor’s patch, to stop this behavior.

What to do
  • Update debian spip to version 4.4.19+dfsg-0+deb13u1.
  • Update debian spip to version 4.4.18+dfsg-1.
  • Update spip spip to version 4.4.18 or later.
Affected software
Ecosystem VendorProductAffected versions
– spip spip < 4.4.18
Debian:13 debian spip < 4.4.19+dfsg-0+deb13u1
Fix: upgrade to 4.4.19+dfsg-0+deb13u1
Debian:14 debian spip < 4.4.18+dfsg-1
Fix: upgrade to 4.4.18+dfsg-1
Ubuntu:Pro:16.04:LTS canonical spip All versions
Original advisory text
SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection
SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter resolving to internal database tables. Attackers can insert a malicious row into the spip_jobs queue with a controlled PHP function and arguments, which is then dynamically executed when the cron processes the queue, resulting in remote code execution.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
1% chance of attack within 30 days
Type
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes
Timeline
Published11 Sep 2026
Updated9 Oct 2026
First seen11 Sep 2026
Track software like this
Free during beta