CVE-2026-33549

SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
Configurations

Configuration 1 (hide)

cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

History

17 Apr 2026, 21:13

Type Values Removed Values Added
Summary
  • (es) SPIP 4.4.10 hasta 4.4.12 antes de 4.4.13 permite la asignación de privilegios no intencionada (de privilegios de administrador) durante la edición de una estructura de datos de autor debido a un manejo incorrecto de STATUT.
First Time Spip spip
Spip
CPE cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
References () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-13.html?lang=fr - () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-13.html?lang=fr - Patch, Release Notes
References () https://git.spip.net/spip/prive/-/commit/b8481a7feb00f301f0ff7d5ce2aad8a772d92c2e - () https://git.spip.net/spip/prive/-/commit/b8481a7feb00f301f0ff7d5ce2aad8a772d92c2e - Patch
References () https://git.spip.net/spip/prive/-/merge_requests/131 - () https://git.spip.net/spip/prive/-/merge_requests/131 - Issue Tracking, Patch

22 Mar 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-22 03:16

Updated : 2026-04-17 21:13


NVD link : CVE-2026-33549

Mitre link : CVE-2026-33549

CVE.ORG link : CVE-2026-33549


JSON object : View

Products Affected

spip

  • spip
CWE
CWE-688

Function Call With Incorrect Variable or Reference as Argument