cbcvebase.
CVE-2026-22205
published 2026-02-26

CVE-2026-22205: SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access…

PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.47%
37.5th percentile
SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive internal data.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianspip< spip 4.4.10+dfsg-1 (forky)spip 4.4.10+dfsg-1 (forky)
spipspip< 4.4.104.4.10
spipspip>= 0 < 4.4.11+dfsg-0+deb13u14.4.11+dfsg-0+deb13u1
spipspip>= 0 < 4.4.10+dfsg-14.4.10+dfsg-1

Detection & IOCsextracted from sources · hover to see the quote

  • Target application is SPIP versions prior to 4.4.10; look for unauthenticated requests reaching protected/authenticated endpoints that should require login
  • The bypass exploits loose PHP type comparisons in authentication logic; monitor for authentication attempts that succeed without valid credentials, particularly where type coercion (e.g., 0 == 'string' or null == false comparisons) may be leveraged
  • ·Vulnerability is scoped as 'local' per Debian security tracker, which may limit remote exploitability depending on deployment configuration
  • ·Debian bullseye remains unpatched ('open'); environments running bullseye with SPIP should be treated as unmitigated until an update is available
  • ·Fixed versions are 4.4.10+dfsg-1 (forky/sid) and 4.4.11+dfsg-0+deb13u1 (trixie); detections should flag any SPIP instance reporting a version below 4.4.10

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.