CVE-2026-22206: SPIP < 4.4.10 SQL Injection RCE via Union & PHP Tags
SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22206?
CVE-2026-22206 is rated as a high severity vulnerability due to the potential for authenticated low-privilege users to execute arbitrary SQL queries.
How do I fix CVE-2026-22206?
To fix CVE-2026-22206, upgrade your SPIP installation to version 4.4.10 or later.
What types of user accounts are affected by CVE-2026-22206?
CVE-2026-22206 affects authenticated low-privilege users who can execute SQL queries through union-based injection techniques.
What impact can CVE-2026-22206 have on my system?
If exploited, CVE-2026-22206 can allow attackers to manipulate database content and potentially achieve remote code execution.
Which versions of SPIP are vulnerable to CVE-2026-22206?
SPIP versions prior to 4.4.10 are vulnerable to CVE-2026-22206.