Threat reportVulnerabilityTL-2026-2221
Pre-Authentication Remote Code Execution in SPIP CMS (CVE-2026-77806) — Actively Exploited
Pre-Authentication Remote Code Execution in SPIP CMS (TL-2026-2221) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-08-29. It has no confirmed attribution, affects SPIP SPIP CMS, references 2 CVEs (CVE-2026-77806, CVE-2026-77647), maps to 7 MITRE ATT&CK techniques (T1059, T1071, T1190), and is covered by 9 detection rules and 8 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 7MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 8Indicators of compromise
Key facts for TL-2026-2221
- Threat ID
- TL-2026-2221
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 8
Malware and tooling in Pre-Authentication Remote Code Execution in SPIP CMS
Malware and tooling: Metasploit module multi/http/spip_x_spip_filtre_rce
How Pre-Authentication Remote Code Execution in SPIP CMS works
SPIP versions before 4.4.21 contain a universal, pre-authentication remote code execution vulnerability (CVE-2026-77806, CVSS 9.8) in which the analyse_resultat_skel() template function mishandles an attacker-supplied X-Spip-Filtre HTTP header, letting an unauthenticated attacker chain PHP filter functions (e.g. intval|_request|system) to execute arbitrary OS commands. The flaw is not mitigated by SPIP's built-in security screen and CERT-FR, SPIP, and multiple vulnerability trackers confirm exploitation attempts in the wild during August 2026; a public Metasploit module was merged 2026-08-24.
SPIP is a widely deployed open-source French CMS used heavily by government, media, and nonprofit sites. On 2026-08-17, SPIP shipped 4.4.20 as an emergency fix for CVE-2026-77647 — a code-injection flaw caused by incorrect identification of <?php blocks and var_export()'s mishandling of a leading '<' character, also reported anonymously via ANSSI and also exploited in the wild before 4.4.20. That patch proved incomplete: on 2026-08-20 SPIP released 4.4.21 to fix a second, related pre-authentication RCE, CVE-2026-77806.
CVE-2026-77806's root cause is a function-call injection flaw in analyse_resultat_skel(), the core SPIP template-rendering function. When a compiled template body contains a `<?php header("X-Spip-Filtre: ..."); ?>` marker, the colon-delimited function names found there are invoked as a chain of PHP filters against the reachable output — but SPIP fails to prevent an attacker from supplying that marker's value directly via the real HTTP request's X-Spip-Filtre header, and from steering user-controlled text into the compiled template body in the first place. The documented path to that compiled body is the forum-preview feature: an unauthenticated visitor's submission to the public forum "texte" field is rendered through the vulnerable skeleton compiler (reachable via endpoints such as ecrire/?exec=forum), giving an attacker a route to the sink without any account or session. The publicly available Metasploit module (multi/http/spip_x_spip_filtre_rce, rapid7/metasploit-framework PR #21790, authored by Julien Voisin/jvoisin, merged 2026-08-24) demonstrates the exploitation primitive: the filter chain `intval|_request|system` first collapses the response body to the string "0" via intval(), then _request() re-reads a POST parameter literally named "0" containing an attacker-supplied OS command string, which system() then executes — yielding unauthenticated, unattended remote code execution with a single crafted HTTP request. The module supports delivery via GET parameter injection, a forum POST to the texte field, or newline injection to smuggle the header value into the request, and was validated against SPIP 4.4.19 and 4.4.20.
Critically, both the CERT-FR advisory and the SPIP vendor bulletin state that this flaw is NOT caught by SPIP's built-in "security screen" (écran de sécurité) — the CMS's dedicated input-filtering defense layer that normally screens malicious-looking public-area submissions — meaning sites relying solely on that built-in protection remain exposed even if otherwise hardened. No CVSS score was published at initial CERT-FR/vendor disclosure, but subsequent NVD/vulnerability-database entries score it CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) against CPE cpe:2.3:a:spip:spip — network-exploitable, low complexity, no privileges or user interaction required, full compromise of confidentiality, integrity, and availability. EPSS places it at roughly the 90th percentile (~4.2% 30-day exploitation probability), and an independent SSVC assessment rates the exploitation method as "Automatable" with "total" technical impact, consistent with the availability of a scriptable, unauthenticated, single-request exploit. As of this research, CVE-2026-77806 has not yet been added to the CISA Known Exploited Vulnerabilities catalog despite confirmed in-the-wild exploitation.
Remediation is a straightforward version upgrade: SPIP 4.4.21 (or later), delivered via spip_loader 7.0.0 or manual download from get.spip.net. Where immediate patching is not feasible, defenders should block or strip inbound X-Spip-Filtre headers at a WAF or reverse proxy in front of any public-facing SPIP deployment, and monitor forum-submission endpoints for anomalous PHP-filter-name strings, since the vendor's own built-in filtering does not stop this vector.
MITRE ATT&CK techniques used in TL-2026-2221
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Initial Access
T1190 Exploit Public-Facing Application
Resource Development
Reconnaissance
T1590 Gather Victim Network Information; T1592 Gather Victim Host Information; T1595 Active Scanning
Affected products and versions in Pre-Authentication Remote Code Execution in SPIP CMS
- SPIP — SPIP CMS
Vulnerable versions: 4.4.19; 4.4.20; all versions prior to 4.4.21
Fixed in: 4.4.21
Remediation for Pre-Authentication Remote Code Execution in SPIP CMS
Patches
- SPIP 4.4.21, released 2026-08-20, distributed via spip_loader 7.0.0 or manual download from get.spip.net
Immediate actions
- Upgrade all internet-facing SPIP instances to 4.4.21 or later immediately
- If immediate patching is not possible, block or strip any inbound X-Spip-Filtre HTTP header at a WAF or reverse proxy in front of the SPIP instance
Workarounds
- Filter/strip the X-Spip-Filtre HTTP request header at a WAF, CDN, or reverse proxy for any SPIP site that cannot be patched immediately
Longer-term hardening
- Do not rely solely on SPIP's built-in security screen (écran de sécurité) for public-facing deployments — this flaw is explicitly not covered by it
- Monitor forum-preview and other template-rendering endpoints (e.g. ecrire/?exec=forum, forum "texte" field submissions) for requests carrying X-Spip-Filtre headers, PHP filter-name chains, or POST parameters literally named "0"
- Track SPIP security bulletins and subscribe to CERT-FR advisories for the SPIP product line given the recent two-CVE, two-patch disclosure cadence
CVEs associated with Pre-Authentication Remote Code Execution in SPIP CMS
Weaknesses (CWE) in Pre-Authentication Remote Code Execution in SPIP CMS
Timeline of Pre-Authentication Remote Code Execution in SPIP CMS
- SPIP releases 4.4.20 as an emergency fix for CVE-2026-77647 (incorrect identification of <?php blocks / var_export mishandling of a leading '<' character), reported anonymously via ANSSI; the Metasploit PR for the related follow-on issue is opened the same day.
- SPIP project publishes 'Mise a jour critique de securite: sortie de SPIP 4.4.21', confirming the flaw is universal/pre-authentication ('sans conditions'), not mitigated by SPIP's built-in security screen, and that exploitation attempts have already been observed in the wild; users directed to update via spip_loader 7.0.0 or get.spip.net.
- SPIP 4.4.20 is found to remain vulnerable; SPIP releases 4.4.21 fixing CVE-2026-77806, a second pre-authentication RCE in analyse_resultat_skel() via the X-Spip-Filtre header reachable through the forum-preview "texte" field.
- CERT-FR publishes advisory CERTFR-2026-AVI-1063, confirming active exploitation of the SPIP flaw.
- CVE-2026-77806 is reserved and published by MITRE at 13:37:42 UTC.
- Rapid7 merges the public Metasploit module multi/http/spip_x_spip_filtre_rce (PR #21790, final commit 9809c1e) into metasploit-framework, authored by Julien Voisin (jvoisin) and reviewed by jheysel-r7, bwatters-r7, and Chocapikk; validated against SPIP 4.4.19 and 4.4.20.
- NVD/OpenCVE last-modify CVE-2026-77806's record, cataloging the CVSS 3.1 9.8 score, CWE-94 classification, EPSS ~4.2% (90th percentile), and an SSVC rating of Automatable exploitation with total technical impact.
Sources cited for Pre-Authentication Remote Code Execution in SPIP CMS
- CERTFR-2026-AVI-1063 — Vulnérabilité dans SPIP
- Mise à jour critique de sécurité : sortie de SPIP 4.4.21
- CVE-2026-77806 Record
- CVE-2026-77806 Detail - NVD - NIST
- CVE-2026-77806 – Unauthenticated Remote Code Execution – SPIP before 4.4.21
- CVE-2026-77806: SPIP: SPIP before 4.4.21 allows unauthenticated RCE
- CVE-2026-77806: SPIP Code Injection (CVSS 9.8) — Fix & Details
- CVE-2026-77806 | INCIBE-CERT | INCIBE
- Critical SPIP Pre-Auth RCE Exploited in the Wild and Added to Metasploit
- Metasploit module multi/http/spip_x_spip_filtre_rce (PR #21790)
- CVE-2026-77806 - Vulnerability Details - OpenCVE
- SPIP Code Injection Vulnerability Allows Unauthenticated Remote Code Execution (CVE-2026-77806)
- CVE-2026-77647 SPIP before 4.4.20 allows unauthenticated RCE
- SPIP Unauthenticated RCE (CVE-2026-77647)
Detection coverage for TL-2026-2221
As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2221 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.