Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-77806: SPIP versions before 4.4.21 let attackers run code
CVE-2026-77806 · published 13 days ago
Summary
Websites using SPIP older than version 4.4.21 can be tricked by anyone on the internet into running unwanted programs on the server. The problem comes from a special HTTP header that the software does not handle safely. Updating SPIP to version 4.4.21 or later fixes the issue.
What to do
- Update debian spip to version 4.4.21+dfsg-0+deb13u1.
- Update spip spip to version 4.4.21 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | spip | spip | < 4.4.21 |
| Debian:11 | debian | spip | All versions |
| Debian:13 | debian | spip |
< 4.4.21+dfsg-0+deb13u1 Fix: upgrade to 4.4.21+dfsg-0+deb13u1
|
| Debian:14 | debian | spip | All versions |
Original advisory text
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request he...
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
References
- https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.htm...
- https://github.com/rapid7/metasploit-framework/pull/21790
- https://github.com/rapid7/metasploit-framework/pull/21790#issuecomment-536803812...
- https://github.com/rapid7/metasploit-framework/pull/21790/commits/b16eca819abb8f...
- https://security-tracker.debian.org/tracker/CVE-2026-77806 Vendor Advisory
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 4%
Type
CWE-94Code Injection
Timeline
Published21 Aug 2026
Updated28 Aug 2026
First seen21 Aug 2026
Monitor software like this
Free during beta