cve-2026-77647

CRITICAL CVSS 9.8 nvd
Description

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.

Timeline
Published
2026-08-20
Last Modified
2026-09-08
CVSS Details
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9 cve@mitre.org
NVD metadata
NVD status
Deferred
Source identifier
cve@mitre.org
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 9.8,
  "datePublished": "2026-08-20T23:16:28.647",
  "dateUpdated": "2026-09-08T19:29:09.680",
  "description": "SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.",
  "id": "CVE-2026-77647",
  "raw": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "SPIP",
            "vendor": "SPIP",
            "versions": [
              {
                "lessThan": "4.4.20",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cve@mitre.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character."
      }
    ],
    "id": "CVE-2026-77647",
    "lastModified": "2026-09-08T19:29:09.680",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.9,
          "source": "cve@mitre.org",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-77647",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-21T19:49:42.530562Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-20T23:16:28.647",
    "references": [
      {
        "source": "cve@mitre.org",
        "url": "https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-20.html"
      },
      {
        "source": "cve@mitre.org",
        "url": "https://lists.debian.org/debian-security-announce/2026/msg00359.html"
      }
    ],
    "sourceIdentifier": "cve@mitre.org",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-94"
          }
        ],
        "source": "cve@mitre.org",
        "type": "Secondary"
      }
    ]
  },
  "severity": "CRITICAL",
  "source": "nvd",
  "title": "SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in Aug..."
}
Enrichment data
View JSON API Download JSON