Junglewise Threat Intelligence

CVE-2026-8429: SPIP remote code execution in private space

CVE-2026-8429 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Spip. Vendors: Spip.

Executive brief

SPIP is a popular open-source content management system used to publish and manage websites. A security vulnerability in the software's administrative interface (the 'private space') allows an attacker with low-level access to execute malicious code on the server. This could lead to a complete takeover of the website, theft of sensitive data, or disruption of services, even if standard security screens are active.

Technical details

A remote code execution (RCE) vulnerability exists in SPIP versions prior to 4.4.14 within the 'private space' (administrative area). The flaw is classified as CWE-94 (Improper Control of Generation of Code) and allows an attacker with low-privileged (PR:L) access to execute arbitrary PHP code in the context of the web server. Notably, the exploit bypasses the 'SPIP security screen' (écran de sécurité), a common hardening measure for the platform. The vulnerability is addressed in version 4.4.14. A separate RCE vulnerability affecting the public space in specific Nginx configurations was also patched in the same release, but this specific entry (CVE-2026-8429) focuses on the private space flaw.

Affected products

  • SPIP SPIP < 4.4.14

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: patched: Released in SPIP 4.4.14
  • 2026-05-12: advisory

References

Related threats