CVE-2026-27472: SPIP < 4.4.9 Blind Server-Side Request Forgery via Syndicated Sites
SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing an authenticated attacker to make the server issue requests to arbitrary internal or external destinations. This vulnerability is not mitigated by the SPIP security screen.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27472?
CVE-2026-27472 is classified as a medium severity vulnerability due to its potential for unauthorized server-side requests.
How do I fix CVE-2026-27472?
To fix CVE-2026-27472, upgrade to SPIP version 4.4.9 or later, where the vulnerability is resolved.
Who is affected by CVE-2026-27472?
CVE-2026-27472 affects all versions of SPIP prior to 4.4.9 that allow editing of syndicated sites.
What type of vulnerability is CVE-2026-27472?
CVE-2026-27472 is a Blind Server-Side Request Forgery (SSRF) vulnerability.
Can an unauthenticated user exploit CVE-2026-27472?
No, CVE-2026-27472 requires authenticated access to exploit the vulnerability.