CRITICAL 9.2 NVD

CVE-2026-66738

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user inpu

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal quoted string context when evaluated as PHP. An authenticated attacker with at minimum editor (redacteur) privileges can submit a single crafted GET request to /ecrire/?exec=navigation to execute arbitrary OS commands in the web server process. MySQL-backed installations are not affected.

References

Published: 2026-08-10 · Source: NVD · Feed updated: 2026-08-10
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-08-10 via NVD.

Risk Timeline

CVE Disclosed2026-08-10 · -1 days ago

Remediation Resources

vulnfeed aggregates 7759 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.