Impact
SPIP versions prior to 4.4.21 enable an attacker to inject arbitrary code by sending a specially crafted X-Spip-Filtre HTTP request header. The application's analyse_resultat_skel function mishandles this header, allowing malicious payloads to be interpreted as code and executed on the server. The flaw results in full compromise of the affected web application, providing the attacker with the ability to execute any commands or upload files on the host system, thereby breaching confidentiality, integrity, and availability. The vulnerability is fundamentally a code injection weakness as defined by CWE‑94.
Affected Systems
The affected software is SPIP by SPIP. All releases before version 4.4.21 are vulnerable, including 4.4.20 and earlier. No other vendor or product is listed in the CNA’s affected version data.
Risk and Exploitability
The CVSS score of 9.8 denotes Critical severity. The EPSS score of 4% indicates a moderate likelihood of exploitation. The recent wild exploitation in August 2026 underscores a tangible threat. The vulnerability is not yet listed in CISA KEV, but the combination of unauthenticated access and the ability to execute arbitrary code makes it highly attractive to threat actors. Exposing the malicious X-Spip‑Filtre header to the public web interface completes the attack path without any authentication or special configuration, allowing an attacker from the Internet to fully compromise the application.
OpenCVE Enrichment