CRITICAL 9.8 CVE-2026-72709 Published 11 Sept 2026

SPIP Unauthenticated Privilege Escalation

Worried this affects one of your servers?

SPIP before version 4.4.18 has a serious security flaw.

SPIP, a popular open-source CMS, contains a missing authorization vulnerability in sensitive actions under 'ecrire/action/'.

Unauthenticated attackers can exploit this vulnerability by supplying only a valid CSRF nonce, bypassing template-level authorization guards, and invoking privileged actions such as 'editer_auteur'. This allows attackers to rewrite arbitrary account passwords, including those of administrator accounts, leading to full account takeover.

Reference: CVE-2026-72709 on NVD

← Back to Security News