CVE-2026-72709: Spip
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can bypass template-level authorization guards through direct HTTP requests to invoke actions such as editer_auteur, enabling arbitrary account password rewrites including administrator accounts and resulting in full account takeover.
Affected products
- Spip Spip: before 4.4.18 (fixed in 4.4.18)
Published 2026-09-11. Last modified 2026-09-15.