Junglewise Threat Intelligence

CVE-2026-8430: SPIP remote code execution in public space via Nginx

CVE-2026-8430 · Severity: high · CVSS 8.1 · Published 2026-05-12

Technologies: Spip. Vendors: Spip.

Executive brief

SPIP is a popular open-source content management system (CMS) used to build and manage websites. A security vulnerability in versions prior to 4.4.14 allows remote attackers to execute malicious code on the web server under specific Nginx configurations. This could lead to a complete takeover of the website, unauthorized access to sensitive data, or disruption of services.

Technical details

A remote code execution (RCE) vulnerability exists in the public space of SPIP versions prior to 4.4.14. The flaw is classified as CWE-94 (Improper Control of Generation of Code) and is triggered under specific Nginx configuration scenarios that interact poorly with SPIP's routing or processing. An unauthenticated remote attacker can exploit this to execute arbitrary PHP code in the context of the web server. Notably, the 'SPIP security screen' (ecran de securite) does not provide protection against this specific flaw. The issue is resolved in SPIP version 4.4.14.

Affected products

  • SPIP SPIP < 4.4.14

Timeline

  • 2026-05-12: disclosed: Vulnerability disclosed and patched in version 4.4.14
  • 2026-05-12: advisory: NVD published the CVE record

References

Related threats