CVE-2026-72710
SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection
Description
SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter resolving to internal database tables. Attackers can insert a malicious row into the spip_jobs queue with a controlled PHP function and arguments, which is then dynamically executed when the cron processes the queue, resulting in remote code execution.
In plain language
AI Worth attentionSPIP versions before 4.4.18 can let an internet attacker take over the website; typical businesses using it should update.
Unauthenticated remote code execution in SPIP’s editer_objet action allows job-queue injection that is executed by the cron worker.
What to do now
- Check whether your website runs SPIP and identify its installed version.
- If it is earlier than 4.4.18, schedule an upgrade to SPIP 4.4.18.
- After upgrading, have your IT provider review recent administrator activity and unexpected scheduled jobs.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-72710 and every CVE in our database. Create a free account — no credit card required.
Create Free Account