Threat reportVulnerabilityTL-2026-2221

Pre-Authentication Remote Code Execution in SPIP CMS (CVE-2026-77806) — Actively Exploited

criticalACTIVE

Pre-Authentication Remote Code Execution in SPIP CMS (TL-2026-2221) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-08-29. It has no confirmed attribution, affects SPIP SPIP CMS, references 2 CVEs (CVE-2026-77806, CVE-2026-77647), maps to 7 MITRE ATT&CK techniques (T1059, T1071, T1190), and is covered by 9 detection rules and 8 indicators of compromise.

CVSS
9.8/10Critical
CVEs
2Referenced vulnerabilities
Techniques
7MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
8Indicators of compromise

Key facts for TL-2026-2221

Threat ID
TL-2026-2221
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target regions
Global
Detection rules
9
Indicators of compromise
8

Malware and tooling in Pre-Authentication Remote Code Execution in SPIP CMS

Malware and tooling: Metasploit module multi/http/spip_x_spip_filtre_rce

How Pre-Authentication Remote Code Execution in SPIP CMS works

SPIP versions before 4.4.21 contain a universal, pre-authentication remote code execution vulnerability (CVE-2026-77806, CVSS 9.8) in which the analyse_resultat_skel() template function mishandles an attacker-supplied X-Spip-Filtre HTTP header, letting an unauthenticated attacker chain PHP filter functions (e.g. intval|_request|system) to execute arbitrary OS commands. The flaw is not mitigated by SPIP's built-in security screen and CERT-FR, SPIP, and multiple vulnerability trackers confirm exploitation attempts in the wild during August 2026; a public Metasploit module was merged 2026-08-24.

SPIP is a widely deployed open-source French CMS used heavily by government, media, and nonprofit sites. On 2026-08-17, SPIP shipped 4.4.20 as an emergency fix for CVE-2026-77647 — a code-injection flaw caused by incorrect identification of <?php blocks and var_export()'s mishandling of a leading '<' character, also reported anonymously via ANSSI and also exploited in the wild before 4.4.20. That patch proved incomplete: on 2026-08-20 SPIP released 4.4.21 to fix a second, related pre-authentication RCE, CVE-2026-77806.

CVE-2026-77806's root cause is a function-call injection flaw in analyse_resultat_skel(), the core SPIP template-rendering function. When a compiled template body contains a `<?php header("X-Spip-Filtre: ..."); ?>` marker, the colon-delimited function names found there are invoked as a chain of PHP filters against the reachable output — but SPIP fails to prevent an attacker from supplying that marker's value directly via the real HTTP request's X-Spip-Filtre header, and from steering user-controlled text into the compiled template body in the first place. The documented path to that compiled body is the forum-preview feature: an unauthenticated visitor's submission to the public forum "texte" field is rendered through the vulnerable skeleton compiler (reachable via endpoints such as ecrire/?exec=forum), giving an attacker a route to the sink without any account or session. The publicly available Metasploit module (multi/http/spip_x_spip_filtre_rce, rapid7/metasploit-framework PR #21790, authored by Julien Voisin/jvoisin, merged 2026-08-24) demonstrates the exploitation primitive: the filter chain `intval|_request|system` first collapses the response body to the string "0" via intval(), then _request() re-reads a POST parameter literally named "0" containing an attacker-supplied OS command string, which system() then executes — yielding unauthenticated, unattended remote code execution with a single crafted HTTP request. The module supports delivery via GET parameter injection, a forum POST to the texte field, or newline injection to smuggle the header value into the request, and was validated against SPIP 4.4.19 and 4.4.20.

Critically, both the CERT-FR advisory and the SPIP vendor bulletin state that this flaw is NOT caught by SPIP's built-in "security screen" (écran de sécurité) — the CMS's dedicated input-filtering defense layer that normally screens malicious-looking public-area submissions — meaning sites relying solely on that built-in protection remain exposed even if otherwise hardened. No CVSS score was published at initial CERT-FR/vendor disclosure, but subsequent NVD/vulnerability-database entries score it CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) against CPE cpe:2.3:a:spip:spip — network-exploitable, low complexity, no privileges or user interaction required, full compromise of confidentiality, integrity, and availability. EPSS places it at roughly the 90th percentile (~4.2% 30-day exploitation probability), and an independent SSVC assessment rates the exploitation method as "Automatable" with "total" technical impact, consistent with the availability of a scriptable, unauthenticated, single-request exploit. As of this research, CVE-2026-77806 has not yet been added to the CISA Known Exploited Vulnerabilities catalog despite confirmed in-the-wild exploitation.

Remediation is a straightforward version upgrade: SPIP 4.4.21 (or later), delivered via spip_loader 7.0.0 or manual download from get.spip.net. Where immediate patching is not feasible, defenders should block or strip inbound X-Spip-Filtre headers at a WAF or reverse proxy in front of any public-facing SPIP deployment, and monitor forum-submission endpoints for anomalous PHP-filter-name strings, since the vendor's own built-in filtering does not stop this vector.

MITRE ATT&CK techniques used in TL-2026-2221

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Initial Access

T1190 Exploit Public-Facing Application

Resource Development

T1588 Obtain Capabilities

Reconnaissance

T1590 Gather Victim Network Information; T1592 Gather Victim Host Information; T1595 Active Scanning

Affected products and versions in Pre-Authentication Remote Code Execution in SPIP CMS

  • SPIP — SPIP CMS
    Vulnerable versions: 4.4.19; 4.4.20; all versions prior to 4.4.21
    Fixed in: 4.4.21

Remediation for Pre-Authentication Remote Code Execution in SPIP CMS

Patches

  • SPIP 4.4.21, released 2026-08-20, distributed via spip_loader 7.0.0 or manual download from get.spip.net

Immediate actions

  • Upgrade all internet-facing SPIP instances to 4.4.21 or later immediately
  • If immediate patching is not possible, block or strip any inbound X-Spip-Filtre HTTP header at a WAF or reverse proxy in front of the SPIP instance

Workarounds

  • Filter/strip the X-Spip-Filtre HTTP request header at a WAF, CDN, or reverse proxy for any SPIP site that cannot be patched immediately

Longer-term hardening

  • Do not rely solely on SPIP's built-in security screen (écran de sécurité) for public-facing deployments — this flaw is explicitly not covered by it
  • Monitor forum-preview and other template-rendering endpoints (e.g. ecrire/?exec=forum, forum "texte" field submissions) for requests carrying X-Spip-Filtre headers, PHP filter-name chains, or POST parameters literally named "0"
  • Track SPIP security bulletins and subscribe to CERT-FR advisories for the SPIP product line given the recent two-CVE, two-patch disclosure cadence

CVEs associated with Pre-Authentication Remote Code Execution in SPIP CMS

CVE-2026-77806, CVE-2026-77647

Weaknesses (CWE) in Pre-Authentication Remote Code Execution in SPIP CMS

CWE-94

Timeline of Pre-Authentication Remote Code Execution in SPIP CMS

  • SPIP releases 4.4.20 as an emergency fix for CVE-2026-77647 (incorrect identification of <?php blocks / var_export mishandling of a leading '<' character), reported anonymously via ANSSI; the Metasploit PR for the related follow-on issue is opened the same day.
  • SPIP project publishes 'Mise a jour critique de securite: sortie de SPIP 4.4.21', confirming the flaw is universal/pre-authentication ('sans conditions'), not mitigated by SPIP's built-in security screen, and that exploitation attempts have already been observed in the wild; users directed to update via spip_loader 7.0.0 or get.spip.net.
  • SPIP 4.4.20 is found to remain vulnerable; SPIP releases 4.4.21 fixing CVE-2026-77806, a second pre-authentication RCE in analyse_resultat_skel() via the X-Spip-Filtre header reachable through the forum-preview "texte" field.
  • CERT-FR publishes advisory CERTFR-2026-AVI-1063, confirming active exploitation of the SPIP flaw.
  • CVE-2026-77806 is reserved and published by MITRE at 13:37:42 UTC.
  • Rapid7 merges the public Metasploit module multi/http/spip_x_spip_filtre_rce (PR #21790, final commit 9809c1e) into metasploit-framework, authored by Julien Voisin (jvoisin) and reviewed by jheysel-r7, bwatters-r7, and Chocapikk; validated against SPIP 4.4.19 and 4.4.20.
  • NVD/OpenCVE last-modify CVE-2026-77806's record, cataloging the CVSS 3.1 9.8 score, CWE-94 classification, EPSS ~4.2% (90th percentile), and an SSVC rating of Automatable exploitation with total technical impact.

Sources cited for Pre-Authentication Remote Code Execution in SPIP CMS

Detection coverage for TL-2026-2221

As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2221 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
8 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats