{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aspipspip/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-72710"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SPIP (\u003c 4.4.18)"],"_cs_severities":["critical"],"_cs_tags":["rce","vulnerability","web-application","sql-injection","cve"],"_cs_type":"advisory","_cs_vendors":["SPIP"],"content_html":"\u003cp\u003eSPIP versions prior to 4.4.18 are affected by a critical remote code execution (RCE) vulnerability within the editer_objet action. The vulnerability arises because the arg parameter resolves SQL table names without validating them against an editable columns allowlist. An attacker possessing a valid nonce can exploit this to inject arbitrary, attacker-controlled rows into the spip_jobs database table.\u003c/p\u003e\n\u003cp\u003eThe injected entries are later processed by the system's cron job queue. Because the application unserializes these malicious payloads during the queue execution process, it leads to arbitrary PHP function execution on the underlying server. Given the severity of this flaw, which carries a CVSS v3.1 base score of 9.8, immediate patching to version 4.4.18 or later is required to prevent unauthorized system compromise. Defenders should focus on monitoring for unauthorized access to administrative actions or suspicious manipulation of the spip_jobs table.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated or low-privileged attackers with a valid nonce to achieve full remote code execution on the hosting server. This enables complete system compromise, potential data exfiltration, and lateral movement within the environment. All sectors deploying SPIP versions below 4.4.18 are at risk of total infrastructure takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all instances of SPIP to version 4.4.18 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit database activity specifically targeting the spip_jobs table for suspicious or unexpected entries.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous requests targeting the editer_objet action, particularly those containing encoded or serialized PHP objects.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T19:15:21Z","date_published":"2026-09-11T19:14:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-spip-rce/","summary":"SPIP versions before 4.4.18 are vulnerable to remote code execution due to improper validation of the arg parameter in the editer_objet action, allowing attackers to inject malicious serialized data into the job queue.","title":"Remote Code Execution in SPIP via editer_objet Action","url":"https://feed.craftedsignal.io/briefs/2026-09-spip-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}