CVE-2026-72709: SPIP < 4.4.18 Missing Authorization via ecrire/action/

Published Sep 11, 2026
·
Updated

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can bypass template-level authorization guards through direct HTTP requests to invoke actions such as editerauteur, enabling arbitrary account password rewrites including administrator accounts and resulting in full account takeover.

Affected Software

1 affected component
Spip SPIP<4.4.18

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SPIP to a version that resolves this vulnerability.

    Fixed in 4.4.18
  2. Compensating control

    Mitigate by blocking unauthenticated access to SPIP ecrire/action/ endpoints (for example via WAF or web server rules) to prevent direct HTTP requests from invoking privileged actions.

Event History

Sep 11, 2026
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness
Oct 14, 58668
Event
via NVD·02:12 AM

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated remote attacker can exploit it. No prior account, user interaction, or elevated privileges are required.

2

What does an attacker need to carry out the attack?

The attacker needs a valid HMAC-SHA256 nonce. The issue allows an attacker to obtain and compute a nonce for the target action as an anonymous user.

3

What is the practical impact of successful exploitation?

An attacker can directly invoke the editer_auteur administrative action over HTTP and reset the password of any account, including an administrator account. This can result in administrative account takeover.

4

Are affected installations vulnerable in their default state?

The provided information identifies affected SPIP versions before 4.4.18 and does not state that any non-default configuration or feature enablement is required. The vulnerable administrative action endpoint is reachable over HTTP.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203