Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-77806: SPIP versions before 4.4.21 let attackers run code

CVE-2026-77806 · published 13 days ago
Summary

Websites using SPIP older than version 4.4.21 can be tricked by anyone on the internet into running unwanted programs on the server. The problem comes from a special HTTP header that the software does not handle safely. Updating SPIP to version 4.4.21 or later fixes the issue.

What to do
  • Update debian spip to version 4.4.21+dfsg-0+deb13u1.
  • Update spip spip to version 4.4.21 or later.
Affected software
Ecosystem VendorProductAffected versions
– spip spip < 4.4.21
Debian:11 debian spip All versions
Debian:13 debian spip < 4.4.21+dfsg-0+deb13u1
Fix: upgrade to 4.4.21+dfsg-0+deb13u1
Debian:14 debian spip All versions
Original advisory text
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request he...
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 4%
Type
CWE-94Code Injection
Timeline
Published21 Aug 2026
Updated28 Aug 2026
First seen21 Aug 2026
Sources
CVE-2026-77806 · MITRE
Monitor software like this
Free during beta