## Overview
SPIP versions prior to 4.4.21 contain a critical vulnerability identified as CVE-2026-77806. This flaw allows unauthenticated remote attackers to execute arbitrary code on affected systems. The vulnerability has been actively exploited in the wild since August 2026.
## Technical Details
The issue arises from improper handling of the X-Spip-Filtre HTTP request header by the `analyse_resultat_skel` function. Attackers can leverage this mishandling to inject malicious code, which can then be executed on the server. The CVSS score for this vulnerability is 9.8, indicating a high level of risk for affected installations.
## Impact
Successful exploitation of CVE-2026-77806 can lead to complete system compromise. Attackers can execute arbitrary code, potentially gaining control over the server and accessing sensitive data. Organizations using vulnerable versions of SPIP should prioritize addressing this vulnerability to mitigate the risk of exploitation.
## Mitigation
Defenders should immediately update SPIP to version 4.4.21 or later. Regularly check for updates and apply security patches as they become available. Additionally, organizations should review their server configurations and monitor for any unusual activity that may indicate exploitation attempts.
CSURFACE Threat Sensor