SPIP Code Injection Vulnerability: Critical CVE-2026-66738 Alert
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- spip (other)
- Patched version
- 4.4.18
An early warning has been issued for a critical code injection vulnerability in SPIP versions before 4.4.18. This vulnerability allows authenticated attackers with minimum editor privileges to execute arbitrary OS commands in the web server process.
What happened
SPIP versions before 4.4.18 reportedly contain a code injection vulnerability when using SQLite-backed installations. An authenticated attacker with minimum editor privileges can exploit this vulnerability to execute arbitrary OS commands in the web server process. This vulnerability is currently under investigation and has not been exploited in the wild. The vulnerability has been assigned the identifier CVE-2026-66738 with a CVSS score of 9.8.
The vulnerability was first flagged on 2026-08-10T16:19:48.607000+00:00. It is recommended to upgrade to SPIP version 4.4.18 or later to mitigate the risk. Users should consult the primary sources for the most current information and updates on this vulnerability.
What to do about it
- Upgrade SPIP to version 4.4.18 or later to mitigate the risk.
- Ensure that all users have the minimum necessary privileges to reduce potential attack vectors.
- Monitor the primary sources for updates and further guidance on this vulnerability.
- Consider implementing additional security measures to protect against potential exploits until the vulnerability is fully patched and understood.
How 0Day would have caught this
spip is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using SPIP versions before 4.4.18.
What should I do right now?
Upgrade SPIP to version 4.4.18 or later to mitigate the risk.
Is this vulnerability being exploited in the wild?
There is no evidence that this vulnerability is being exploited in the wild at this time.
Where can I find more information about this vulnerability?
Consult the primary sources including the NVD entry for CVE-2026-66738.