CVE-2026-33549General(spip / spip)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-688

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spip

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
spip

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-22: 3Technical Details · 2026-03-22: 203-22
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33549 SPIP Privilege Escalation Vulnerability in Versions 4.4.10 Through 4.4.12 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33549

    Post summary

    The post references a privilege escalation vulnerability (CVE‑2026‑33549) in SPIP 4.4.10‑4.4.12 but provides only minimal technical detail and no evidence of exploitation or remediation.

    0001032
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33549 📊 Severity: 6.7 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33549 #CVE-2026-33549 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/MI4iDlrroL

    Post summary

    Tweet announces CVE‑2026‑33549 with a medium severity rating but gives no additional technical details or mitigation information.

    0000016
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33549 SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because o… https://www.cve.org/CVERecord?id=CVE-2026-33549

    Post summary

    This post discloses a privilege escalation flaw in SPIP versions 4.4.10 to 4.4.12, where an attacker can gain administrator rights by editing an author data structure.

    0000070
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appspipspip---

Explore more