CVE-2026-72710: SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection

Published Sep 11, 2026
·
Updated

SPIP before 4.4.18 contains a mass assignment vulnerability in the editerobjet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champseditables allowlist by supplying an attacker-controlled arg parameter resolving to internal database tables. Attackers can insert a malicious row into the spipjobs queue with a controlled PHP function and arguments, which is then dynamically executed when the cron processes the queue, resulting in remote code execution.

Affected Software

1 affected component
Spip SPIP<4.4.18

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SPIP to a version that resolves this vulnerability.

    Fixed in 4.4.18
  2. Compensating control

    If upgrading is not immediately possible, block unauthenticated access to the SPIP endpoint/action that exposes the mass assignment in editer_objet (before 4.4.18), since it allows writing arbitrary rows via attacker-controlled arg resolving to internal database tables.

Event History

Sep 11, 2026
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness
Oct 14, 58668
Event
via NVD·01:23 AM

Frequently Asked Questions

1

What must an attacker have to exploit this issue?

An attacker needs a valid nonce and must be able to submit a request to the editer_objet action using arg=job/0 with crafted fonction and args values. No additional privileges or user interaction are identified in the provided data.

2

When does the injected payload execute?

The crafted job is stored in the spip_jobs table and executes when the cron job queue is drained. At that point, the supplied values are unserialized and can result in arbitrary PHP function execution on the underlying system.

3

Which installations are affected?

SPIP versions earlier than 4.4.18 are affected according to the provided information. The data does not state whether any specific configuration changes, plugins, or deployment modes are required.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203