CVE-2026-27475Disclosure(spip / spip)

LOWCVSS 9.2 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition requiring prior access or another vulnerability) can trigger arbitrary object instantiation and potentially achieve code execution. The use of serialized data in these components has been deprecated and will be removed in SPIP 5. This vulnerability is not mitigated by the SPIP security screen.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spip

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
spip

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-19: 2Technical Details · 2026-02-19: 202-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27475 Insecure Deserialization Vulnerability in SPIP before 4.4... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27475 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE-2026-27475, an insecure deserialization flaw in SPIP versions prior to 4.4, without providing PoC, exploit code, or patch details.

    0001051
    4.0K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27475** pertains to an **Insecure Deserialization** flaw present in **SPIP** versions prior to **4.4.9**. The vulnerability exists within the handling of serialized data in specific components, namely the **table_valeur filter** and the **DATA iterator**, which accept serialized input from users or other sources. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-27475

    Post summary

    The post announces an insecure deserialization flaw in SPIP versions prior to 4.4.9, detailing affected components, but does not provide PoC, exploit, patch, or evidence of active exploitation.

    0000046
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appspipspip---

Explore more