SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive internal data.
References
| Link | Resource |
|---|---|
| https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-10.html | Release Notes |
| https://git.spip.net/spip/spip | Product |
| https://www.vulncheck.com/advisories/spip-sql-injection-rce-via-union-php-tags | Third Party Advisory |
Configurations
History
02 Mar 2026, 16:08
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Spip spip
Spip |
|
| CPE | cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* | |
| References | () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-10.html - Release Notes | |
| References | () https://git.spip.net/spip/spip - Product | |
| References | () https://www.vulncheck.com/advisories/spip-sql-injection-rce-via-union-php-tags - Third Party Advisory |
27 Feb 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
27 Feb 2026, 14:06
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
26 Feb 2026, 21:28
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-26 21:28
Updated : 2026-03-02 16:08
NVD link : CVE-2026-22205
Mitre link : CVE-2026-22205
CVE.ORG link : CVE-2026-22205
JSON object : View
Products Affected
spip
- spip
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
