CVE-2026-72709: SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur

Published Sep 11, 2026
·
Updated

SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by supplying a valid HMAC-SHA256 nonce without any server-side permission check via autoriser(). Attackers can obtain a valid nonce, compute it for any action as the anonymous user, and invoke the editerauteur action directly over HTTP to reset the password of any user account, including the administrator.

Affected Software

1 affected component
Spip SPIP<4.4.18

Event History

Sep 11, 2026
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated remote attacker can exploit it. No prior account, user interaction, or elevated privileges are required.

2

What does an attacker need to carry out the attack?

The attacker needs a valid HMAC-SHA256 nonce. The issue allows an attacker to obtain and compute a nonce for the target action as an anonymous user.

3

What is the practical impact of successful exploitation?

An attacker can directly invoke the editer_auteur administrative action over HTTP and reset the password of any account, including an administrator account. This can result in administrative account takeover.

4

Are affected installations vulnerable in their default state?

The provided information identifies affected SPIP versions before 4.4.18 and does not state that any non-default configuration or feature enablement is required. The vulnerable administrative action endpoint is reachable over HTTP.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203