CVE-2026-33549: High severity Spip SPIP vulnerability
Published Mar 22, 2026
·Updated
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
Affected Software
2 affected components
Spip SPIP>=4.4.10<=4.4.12
Spip SPIP>=4.4.10<4.4.13
Remediation
Patch Available
Event History
Mar 22, 2026
CVE Published
via MITRE·02:03 AM
Data Sourced
via MITRE·02:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 9, 58271
Event
via NVD·01:50 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-33549?
CVE-2026-33549 has a medium severity due to the potential for unintended privilege escalation.
2
How do I fix CVE-2026-33549?
To fix CVE-2026-33549, upgrade SPIP to version 4.4.13 or later.
3
Which versions of SPIP are affected by CVE-2026-33549?
SPIP versions 4.4.10 through 4.4.12 are affected by CVE-2026-33549.
4
What kind of vulnerability is CVE-2026-33549?
CVE-2026-33549 is a privilege escalation vulnerability that can allow unauthorized administrators access.
5
Is there a workaround for CVE-2026-33549?
There is no confirmed workaround for CVE-2026-33549; upgrading is the recommended action.