cbcvebase.
CVE-2026-33549
published 2026-03-22

CVE-2026-33549: SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure…

PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.24%
15.1th percentile
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianspip< spip 4.4.13+dfsg-1 (forky)spip 4.4.13+dfsg-1 (forky)
spipspip>= 0 < 4.4.13+dfsg-0+deb13u14.4.13+dfsg-0+deb13u1
spipspip>= 0 < 4.4.13+dfsg-14.4.13+dfsg-1
spipspip>= 4.4.10 < 4.4.134.4.13

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_debian6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.