← Terug naar overzicht

CVE-2026-77806 is a critical unauthenticated remote code execution vulnerability affecting SPIP versions prior to 4.4.21. The flaw allows attackers to inject arbitrary code via the X-Spip-Filtre HTTP request header, which is improperly handled by the analyse_resultat_skel function. The vulnerability has been actively exploited in the wild as of August 2026. A critical security update (SPIP 4.4.21) has been released to address the issue. A Metasploit module has been developed and merged into the framework, indicating widespread exploit availability. No authentication is required to exploit this vulnerability, making it particularly dangerous for publicly exposed SPIP installations. Organizations running SPIP are urged to update immediately to version 4.4.21 or later.

Affected products

  • SPIP before 4.4.21

Related CVE's

  • CVE-2026-77806

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities