CVE-2026-33549
published 2026-03-22CVE-2026-33549: SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.24%
15.1th percentile
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | spip | < spip 4.4.13+dfsg-1 (forky) | spip 4.4.13+dfsg-1 (forky) |
| spip | spip | >= 0 < 4.4.13+dfsg-0+deb13u1 | 4.4.13+dfsg-0+deb13u1 |
| spip | spip | >= 0 < 4.4.13+dfsg-1 | 4.4.13+dfsg-1 |
| spip | spip | >= 4.4.10 < 4.4.13 | 4.4.13 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_debian6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-33549: SPIP 4
osv·2026-03-22·CVSS 6.7
CVE-2026-33549 [MEDIUM] CVE-2026-33549: SPIP 4
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
GHSA
GHSA-x592-5gwh-wjg9: SPIP 4
ghsa_unreviewed·2026-03-22
CVE-2026-33549 [MEDIUM] CWE-688 GHSA-x592-5gwh-wjg9: SPIP 4
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
Debian
CVE-2026-33549: spip - SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment ...
vendor_debian·2026·CVSS 6.7
CVE-2026-33549 [MEDIUM] CVE-2026-33549: spip - SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment ...
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
Scope: local
bullseye: open
forky: resolved (fixed in 4.4.13+dfsg-1)
sid: resolved (fixed in 4.4.13+dfsg-1)
trixie: resolved (fixed in 4.4.13+dfsg-0+deb13u1)
No detection rules found.
No public exploits indexed.
2026-03-22
Published