CVE-2026-22205: SPIP < 4.4.10 Authentication Bypass via PHP Type Juggling
SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive internal data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22205?
CVE-2026-22205 is classified as a high severity vulnerability due to its potential to allow unauthenticated access to protected information.
How do I fix CVE-2026-22205?
To fix CVE-2026-22205, update SPIP to version 4.4.10 or later to mitigate the authentication bypass issue.
What types of attacks can exploit CVE-2026-22205?
CVE-2026-22205 can be exploited through type juggling in authentication logic, allowing attackers to bypass login verification.
Which versions of SPIP are affected by CVE-2026-22205?
All SPIP versions prior to 4.4.10 are affected by CVE-2026-22205, making them vulnerable to authentication bypass.
Who is at risk from CVE-2026-22205?
Any users of SPIP versions before 4.4.10 are at risk of CVE-2026-22205 as they may unintentionally expose protected information.