ctipilot.ch

SPIP — unconditional pre-authentication RCE in all versions before 4.4.20, exploited in the wild; note 4.4.20 is itself affected by a second, unnumbered flaw fixed in 4.4.21

cve · CVE-2026-77647

Coverage timeline
1
first 2026-08-22 → last 2026-08-22
Peak priority
high
1 high
Sources cited
4
3 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
SPIP

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-22/spip-two-unconditional-preauth-rce-releases-three-days-apart · ATT&CK page ↗

Story timeline

  1. 2026-08-22SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited — and only the first one has a CVE
    trending-vulnerabilities4.4.20 fixed a flaw in every version; 4.4.21 fixed a second one in 4.4.20 itself, with no identifier to track it by

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • blog.spip.net2 (50%)
  • cert.ssi.gouv.fr1 (25%)
  • euvd.enisa.europa.eu1 (25%)

explore in graph

Entries about SPIP — unconditional pre-authentication RCE in all versions before 4.4.20, exploited in the wild; note 4.4.20 is itself affected by a second, unnumbered flaw fixed in 4.4.21 (1)

2026-08-22 · view entry permalink →

HIGHCVE-2026-77647exploitedNATOA2

SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited — and only the first one has a CVE

SPIP's maintainers published a critical security release on Monday 17 August 2026 and another on Thursday 20 August. The release notes describe their respective flaws in near-identical language, and the wording is unusually unhedged for a vendor bulletin: 4.4.20 fixes an unconditional, no-prerequisites pre-authentication remote code execution vulnerability affecting all versions of SPIP (SPIP, 2026-08-17), and 4.4.21 fixes an unconditional, no-prerequisites pre-authentication remote code execution vulnerability affecting version 4.4.20 — the release that had just shipped three days earlier (SPIP, 2026-08-20). Both notes then carry the same follow-on sentence word for word: the flaw is not handled by the security screen, it is imperative to update the site very quickly, and exploitation attempts have already been observed in the wild. The security screen — SPIP's own request-filtering layer, which many administrators treat as a standing compensating control against exactly this bug class — is therefore ruled out by the vendor as a mitigation for both. Both were reported anonymously through France's national cybersecurity agency, and the earlier one credits a researcher by handle for help with the analysis and the fix (SPIP, 2026-08-17).

Only the first of the two has an identifier. CVE-2026-77647 is the 4.4.20 fix: the EU vulnerability database record cites that release note directly, bounds the affected range as everything below 4.4.20, scores it CVSS 3.1 9.8 with an EPSS of 0.82, and states in its own description that the flaw is exploited in the wild in August 2026 (ENISA EU Vulnerability Database, 2026-08-20). Its published root cause is incorrect identification of PHP open tags combined with a value-exporting function's mishandling of certain cases such as the presence of a < character (ENISA EU Vulnerability Database, 2026-08-20). The 4.4.21 flaw has no CVE, no CWE and no published root cause; CERT-FR relayed it as an advisory the following day, recording remote code execution as the risk, giving the affected range as all versions before 4.4.21, and attributing the active-exploitation statement to the vendor rather than asserting it itself (CERT-FR, 2026-08-21). Whether it is a bypass of the fix that shipped three days earlier or an independent flaw of the same shape is not something any source says, and this entry does not guess.

Triage: a public CMS receives constant automated probing, so request volume and 404 noise separate nothing. The discriminator is what happens after a request rather than the request itself — a web-server worker process spawning a shell or interpreter child, or a file appearing under the document root whose modification time matches no deployment, upgrade or editorial action. On a platform this widely deployed across French-language public administration, and with the earlier flaw's CVE record already recording in-the-wild exploitation, the base rate for that sequence being benign is low.

Cette version corrige une vulnérabilité universelle (sans conditions) pré-authentification RCE qui touche toutes les versions de SPIP.

SPIP (4.4.20 release note)

Cette version corrige une vulnérabilité universelle (sans conditions) pré-authentification RCE qui touche la version 4.4.20 de SPIP.

SPIP (4.4.21 release note)

Systèmes affectés SPIP versions antérieures à 4.4.21

L'éditeur indique que cette vulnérabilité est activement exploitée.

CERT-FR / ANSSI 2026-08-21

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026.

ENISA EU Vulnerability Database 2026-08-20
vulnerability22 Aug 05:07Zmulti-sourceOpen finding ↗