CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-66738

highCVSS 8.8covered by 2 sourcesfirst seen 2026-08-10
SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal quoted string context when evaluated as PHP. An authenticated attacker with at minimum editor (redacteur) privileges can submit a single crafted GET request to /ecrire/?exec=navigation to execute arbitrary OS commands in the web server process. MySQL-backed installations are not affected.

CSIRTS triage

What
SPIP contains remote code execution, SQL injection, and server-side request forgery vulnerabilities.
Who is affected
SPIP website installations with vulnerable versions.
Urgency
Remote code execution is critical and requires immediate remediation.
Action
Apply DSA-6435-1 security update from Debian or check SPIP's official security advisories for the patched version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-66738

Get an email if CVE-2026-66738 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-66738

CVE.org record

Embed the live status

CVE-2026-66738 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-66738 status](https://www.csirts.com/badge/CVE-2026-66738)](https://www.csirts.com/cve/CVE-2026-66738)