CVE-2026-72709: SPIP < 4.4.18 Missing Authorization via ecrire/action/
SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can bypass template-level authorization guards through direct HTTP requests to invoke actions such as editerauteur, enabling arbitrary account password rewrites including administrator accounts and resulting in full account takeover.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SPIPto a version that resolves this vulnerability.Fixed in 4.4.18 - Compensating control
Mitigate by blocking unauthenticated access to SPIP ecrire/action/ endpoints (for example via WAF or web server rules) to prevent direct HTTP requests from invoking privileged actions.
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote attacker can exploit it. No prior account, user interaction, or elevated privileges are required.
What does an attacker need to carry out the attack?
The attacker needs a valid HMAC-SHA256 nonce. The issue allows an attacker to obtain and compute a nonce for the target action as an anonymous user.
What is the practical impact of successful exploitation?
An attacker can directly invoke the editer_auteur administrative action over HTTP and reset the password of any account, including an administrator account. This can result in administrative account takeover.
Are affected installations vulnerable in their default state?
The provided information identifies affected SPIP versions before 4.4.18 and does not state that any non-default configuration or feature enablement is required. The vulnerable administrative action endpoint is reachable over HTTP.