CVE-2026-8430: SPIP < 4.4.14 Remote Code Execution via nginx
SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability through specific nginx configuration scenarios to achieve code execution, and this issue is not mitigated by the SPIP security screen.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SPIPto a version that resolves this vulnerability.Fixed in 4.4.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8430?
CVE-2026-8430 is rated as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-8430?
To fix CVE-2026-8430, upgrade your SPIP installation to version 4.4.14 or later.
What types of systems are affected by CVE-2026-8430?
CVE-2026-8430 affects SPIP versions prior to 4.4.14 running on certain nginx configurations.
What are the risks of leaving CVE-2026-8430 unpatched?
Leaving CVE-2026-8430 unpatched exposes the system to remote code execution attacks, potentially allowing attackers to gain control of the web server.
Can CVE-2026-8430 be exploited remotely?
Yes, CVE-2026-8430 can be exploited remotely due to the nature of the vulnerability in the public space of SPIP.