Description
The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for public ticket pages. The plugin appends untrusted request parameters into HTML that is later rendered by a template using unfiltered environment rendering (#ENV**), which disables SPIP output filtering. As a result, an unauthenticated attacker can inject crafted content that is evaluated through SPIP's template processing chain, leading to execution of code in the context of the web server.
Published: 2026-02-25
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The SPIP tickets plugin contains an unauthenticated remote code execution flaw in versions prior to 4.3.3. The flaw arises when the forum preview handling for public ticket pages appends untrusted request parameters into HTML, which is later rendered by a template using unfiltered environment rendering (#ENV). This bypasses SPIP’s output filtering and allows an attacker to inject crafted content that is evaluated by the template processing chain, resulting in execution of code in the web server context.

Affected Systems

Console and web servers running the SPIP tickets plugin with a version prior to 4.3.3 are affected. The vulnerability is present in all releases of the tickets plugin below the 4.3.3 update that users should migrate to.

Risk and Exploitability

The flaw carries a CVSS score of 9.3, indicating critical severity. Its EPSS score is currently below 1 %, suggesting low exploitation probability at present, and it is not listed in CISA’s Known Exploited Vulnerabilities catalog. However, the vulnerability is exploitable by any unauthenticated user through the public ticket page preview interface, requiring no special credentials. The combination of a high severity rating and the lack of authentication requirements means that an attacker could achieve remote code execution with minimal effort once the flaw existed in the environment.

Generated by OpenCVE AI on April 16, 2026 at 16:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SPIP tickets plugin to version 4.3.3 or newer.
  • Disable or restrict the preview functionality for public ticket pages until the plugin is upgraded.
  • Apply additional web server hardening, such as restricting template rendering to trusted contexts or enabling output filtering on the affected pages.

Generated by OpenCVE AI on April 16, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 05 Mar 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Centreon
Centreon open Tickets
CPEs cpe:2.3:a:centreon:open_tickets:*:*:*:*:*:*:*:*
Vendors & Products Centreon
Centreon open Tickets

Fri, 27 Feb 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:spip:tickets:*:*:*:*:*:*:*:*

Fri, 27 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Feb 2026 20:30:00 +0000


Wed, 25 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 25 Feb 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Spip
Spip tickets
Vendors & Products Spip
Spip tickets

Wed, 25 Feb 2026 04:15:00 +0000

Type Values Removed Values Added
Description The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for public ticket pages. The plugin appends untrusted request parameters into HTML that is later rendered by a template using unfiltered environment rendering (#ENV**), which disables SPIP output filtering. As a result, an unauthenticated attacker can inject crafted content that is evaluated through SPIP's template processing chain, leading to execution of code in the context of the web server.
Title SPIP tickets < 4.3.3 Unauthenticated RCE
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Centreon Open Tickets
Spip Tickets
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-05T01:31:25.599Z

Reserved: 2026-02-23T21:38:48.841Z

Link: CVE-2026-27744

cve-icon Vulnrichment

Updated: 2026-02-25T15:35:25.560Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-25T04:16:04.973

Modified: 2026-02-27T19:41:32.743

Link: CVE-2026-27744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T16:15:08Z

Weaknesses