CVE-2026-22205

SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive internal data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

History

02 Mar 2026, 16:08

Type Values Removed Values Added
First Time Spip spip
Spip
CPE cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
References () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-10.html - () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-10.html - Release Notes
References () https://git.spip.net/spip/spip - () https://git.spip.net/spip/spip - Product
References () https://www.vulncheck.com/advisories/spip-sql-injection-rce-via-union-php-tags - () https://www.vulncheck.com/advisories/spip-sql-injection-rce-via-union-php-tags - Third Party Advisory

27 Feb 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) Las versiones de SPIP anteriores a la 4.4.10 contienen una vulnerabilidad de omisión de autenticación causada por la manipulación de tipos de PHP que permite a atacantes no autenticados acceder a información protegida. Los atacantes pueden explotar comparaciones de tipos laxas en la lógica de autenticación para omitir la verificación de inicio de sesión y recuperar datos internos sensibles.

26 Feb 2026, 21:28

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 21:28

Updated : 2026-03-02 16:08


NVD link : CVE-2026-22205

Mitre link : CVE-2026-22205

CVE.ORG link : CVE-2026-22205


JSON object : View

Products Affected

spip

  • spip
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel