CVE-2026-72709

NameCVE-2026-72709
DescriptionSPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by supplying a valid HMAC-SHA256 nonce without any server-side permission check via autoriser(). Attackers can obtain a valid nonce, compute it for any action as the anonymous user, and invoke the editer_auteur action directly over HTTP to reset the password of any user account, including the administrator.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
spip (PTS)trixie4.4.15+dfsg-0+deb13u1vulnerable
trixie (security)4.4.23+dfsg-0+deb13u1fixed
forky, sid4.4.23+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
spipsourcetrixie4.4.19+dfsg-0+deb13u1
spipsource(unstable)4.4.18+dfsg-1

Notes

https://blog.lexfo.fr/casse-spip-sqli-to-rce.html
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html

Search for package or bug name: Reporting problems