Description
SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter resolving to internal database tables. Attackers can insert a malicious row into the spip_jobs queue with a controlled PHP function and arguments, which is then dynamically executed when the cron processes the queue, resulting in remote code execution.
Published: 2026-09-11
Score: 9.3 Critical
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a mass assignment flaw in SPIP's editer_objet action before 4.4.18. It permits unauthenticated attackers to write arbitrary rows to any SQL table that lacks a champs_editables allowlist by providing an arg parameter that resolves to internal database tables. By inserting a malicious row into the spip_jobs queue with a controlled PHP function and arguments, the cron daemon dynamically executes this payload when the queue is processed, yielding remote code execution. This failure of input validation and sanitization corresponds to CWE‑915.

Affected Systems

SPIP installations of any version earlier than 4.4.18 are affected. The vendor, SPIP, publishes a security update in version 4.4.18 that addresses this issue. The affected component is the editer_objet.php script and the spip_jobs queue mechanism.

Risk and Exploitability

The CVSS score of 9.3 marks this flaw as critical. The attack does not require authentication; an unauthenticated user can send a crafted request to editer_objet.php with an arg value that points to internal database tables. The injected row in the spip_jobs queue is executed only when the cron daemon drains the queue, allowing the attacker to trigger code execution at a later time. The EPSS score is <1%, indicating a low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The combination of critical severity, unauthenticated access, and delayed execution makes this a high‑priority issue that warrants immediate remediation.

Generated by OpenCVE AI on September 21, 2026 at 04:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SPIP application to version 4.4.18 or later immediately.
  • Disable or remove the job queue feature from sites that do not rely on scheduled tasks until the patch is applied.
  • If non‑privileged user and scrub the spip_jobs table to remove any injected rows before applying the fix.

Generated by OpenCVE AI on September 21, 2026 at 04:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing attackers with a valid nonce to inject attacker-controlled rows into the spip_jobs table. Attackers can supply arg=job/0 with crafted fonction and args values, which are later unserialized and executed when the cron job queue is drained, resulting in arbitrary PHP function execution on the underlying system. SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter resolving to internal database tables. Attackers can insert a malicious row into the spip_jobs queue with a controlled PHP function and arguments, which is then dynamically executed when the cron processes the queue, resulting in remote code execution.
Title SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Spip
Spip spip
Vendors & Products Spip
Spip spip
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing attackers with a valid nonce to inject attacker-controlled rows into the spip_jobs table. Attackers can supply arg=job/0 with crafted fonction and args values, which are later unserialized and executed when the cron job queue is drained, resulting in arbitrary PHP function execution on the underlying system.
Title SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection
Weaknesses CWE-915
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:20:28.102Z

Reserved: 2026-08-10T13:02:52.001Z

Link: CVE-2026-72710

cve-icon Vulnrichment

Updated: 2026-09-11T16:58:43.683Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T17:18:58.907

Modified: 2026-09-15T03:17:05.947

Link: CVE-2026-72710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:30:08Z

Weaknesses
  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes