Skip to main content
QUIETLYTIC
Vulnerability

SPIP Code Injection (CVE-2026-77806)

CVE-2026-77806 is a CVSS 9.8 code injection flaw in the SPIP CMS allowing unauthenticated RCE, with NVD itself noting exploitation in the wild.

CVE-2026-77806
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
SPIP, SPIP (before 4.4.21)

CVE-2026-77806 carries a CVSS 3.1 base score of 9.8 against SPIP, an open-source content management system used primarily by French-language publishing and editorial sites. NVD classifies it as CWE-94 (Improper Control of Generation of Code) and states the flaw is fixed in version 4.4.21, meaning all earlier versions are affected. VulnCheck’s KEV feed independently reports the CVE as exploited, dated August 21, 2026.

Unusually for our recent VulnCheck-only coverage, NVD’s own description states directly that this CVE was “exploited in the wild in August 2026,” rather than that fact coming from VulnCheck’s catalog alone. That is a meaningfully different evidentiary position than our other single-source advisories this batch: two separate documents (NVD’s record and VulnCheck’s KEV entry) independently state exploitation occurred, even though CISA has not added this CVE to its own Known Exploited Vulnerabilities catalog as of our most recent ingestion on September 19, 2026, and no Binding Operational Directive 26-04 obligation follows without that specific listing.

What the flaw is

NVD’s description identifies the vulnerable code path as analyse_resultat_skel, a function involved in SPIP’s template-result parsing, which mishandles a value taken from the X-Spip-Filtre HTTP request header. NVD states this mishandling allows unauthenticated remote attackers to execute arbitrary code. Because the vulnerable input is an HTTP header rather than a form field or URL parameter, this class of flaw can be easy to miss in access logs unless an operator is specifically inspecting request headers rather than just paths and query strings.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-94 classification, the fixed version (4.4.21), and the specific vulnerable function and header (analyse_resultat_skel, X-Spip-Filtre) all trace to NVD alone.
  • Elevated evidentiary weight on exploitation — while VulnCheck KEV remains the source for the specific August 21, 2026 catalog-addition date, NVD’s own description independently states the CVE was exploited in the wild, which is a second document corroborating the underlying fact of exploitation even though neither constitutes CISA KEV listing.
  • High exploitation probability — FIRST’s EPSS model scores this CVE at 0.04201, a 90.4th percentile score as of our ingestion, consistent with confirmed in-the-wild exploitation of an unauthenticated, low-complexity remote code execution flaw.

No field is in conflict between our sources. The fixed version (4.4.21) is stated directly in NVD’s record.

Why this matters

SPIP’s user base skews toward publishing and editorial organizations, a sector where staffing for security operations is often thinner than in commercial software companies, and where an active in-the-wild exploitation report — independently stated by both NVD and VulnCheck — should be read as a signal to patch immediately rather than to wait for further corroboration. The vulnerable input being an HTTP header rather than a more commonly logged and monitored request component adds a practical detection challenge on top of the underlying severity.

Because NVD names a specific fixed version, remediation here is unambiguous: any SPIP instance running a pre-4.4.21 release should be upgraded immediately given the confirmed exploitation.

Frequently Asked Questions

What is CVE-2026-77806? A CVSS 9.8 code injection vulnerability (CWE-94) in the SPIP content management system, fixed in version 4.4.21, allowing unauthenticated remote code execution via the X-Spip-Filtre HTTP request header.

Is CVE-2026-77806 being actively exploited? Yes, and unusually for this batch, both NVD’s own record and VulnCheck’s KEV feed independently state this. VulnCheck dates the catalog addition to August 21, 2026. CISA has not added this CVE to its own KEV catalog as of our September 19, 2026 ingestion.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing specifically, and this CVE is not CISA-listed, even though both NVD and VulnCheck confirm exploitation independently.

Which version fixes this? Version 4.4.21, per NVD’s own record.

What makes this vulnerability harder to detect than a typical URL-based exploit? NVD states the vulnerable input arrives via the X-Spip-Filtre HTTP request header rather than a URL parameter or form field, which many logging and monitoring setups pay less attention to than request paths and query strings.


Severity, vector, weakness classification, vulnerable function, and fixed version sourced from the National Vulnerability Database record for CVE-2026-77806, which independently states in-the-wild exploitation. SPIP’s own security release announcement: critical security update for SPIP 4.4.21. Exploitation status is separately reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite, dated August 21, 2026. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools