CVE-2026-66738
SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal quoted string context when evaluated as PHP. An authenticated attacker with at minimum editor (redacteur) privileges can submit a single crafted GET request to /ecrire/?exec=navigation to execute arbitrary OS commands in the web server process. MySQL-backed installations are not affected.
CSIRTS triage
- What
- SPIP contains remote code execution, SQL injection, and server-side request forgery vulnerabilities.
- Who is affected
- SPIP website installations with vulnerable versions.
- Urgency
- Remote code execution is critical and requires immediate remediation.
- Action
- Apply DSA-6435-1 security update from Debian or check SPIP's official security advisories for the patched version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-66738
Get an email if CVE-2026-66738 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownDSA-6435-1 spip - security updatedebian · 2026-08-12
- highCVE-2026-66738: SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The…nvd · 2026-08-10
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-66738)