CVE-2026-72710: SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection
SPIP before 4.4.18 contains a mass assignment vulnerability in the editerobjet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champseditables allowlist by supplying an attacker-controlled arg parameter resolving to internal database tables. Attackers can insert a malicious row into the spipjobs queue with a controlled PHP function and arguments, which is then dynamically executed when the cron processes the queue, resulting in remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SPIPto a version that resolves this vulnerability.Fixed in 4.4.18 - Compensating control
If upgrading is not immediately possible, block unauthenticated access to the SPIP endpoint/action that exposes the mass assignment in editer_objet (before 4.4.18), since it allows writing arbitrary rows via attacker-controlled arg resolving to internal database tables.
Event History
Frequently Asked Questions
What must an attacker have to exploit this issue?
An attacker needs a valid nonce and must be able to submit a request to the editer_objet action using arg=job/0 with crafted fonction and args values. No additional privileges or user interaction are identified in the provided data.
When does the injected payload execute?
The crafted job is stored in the spip_jobs table and executes when the cron job queue is drained. At that point, the supplied values are unserialized and can result in arbitrary PHP function execution on the underlying system.
Which installations are affected?
SPIP versions earlier than 4.4.18 are affected according to the provided information. The data does not state whether any specific configuration changes, plugins, or deployment modes are required.