CVE-2026-66738Disclosure

MEDIUMCVSS 7.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal quoted string context when evaluated as PHP. An authenticated attacker with at minimum editor (redacteur) privileges can submit a single crafted GET request to /ecrire/?exec=navigation to execute arbitrary OS commands in the web server process. MySQL-backed installations are not affected.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-10); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-10: 3Mentions · 2026-08-11: 1PoC Mentioned / Linked · 2026-08-10: 1Exploit Tool / Code · 2026-08-10: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-08-10: 2Technical Details · 2026-08-11: 108-1008-11
Signal classification3 categories
Disclosure
250.0%
Exploit
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-103
Disclosure2Exploit1
2026-08-111
Patch1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-66738 SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, whi… https://www.cve.org/CVERecord?id=CVE-2026-66738

    Post summary

    A code injection vulnerability (CVE-2026-66738) was disclosed in SPIP versions prior to 4.4.18, affecting SQLite-backed installations through the navigation menu endpoint.

    010401.7K
    58.1K followersView on X
  • Aretiq.AI@AretiqAI
    Exploit

    ARETIQ Daily Vulnerability Bulletin — August 10, 2026 🔴 CRITICAL: CVE-2026-72565 (tencent/apijson) AAS 12.6 — PoC available 🔴 CRITICAL: CVE-2026-66738 (spip/spip) AAS 12.2 — exploit available 🔴 CRITICAL: dokploy/dokploy (4 CVEs) AAS 12.1 — exploit available 38 vulnerabilities — CRITICAL: 6, HIGH: 32 Full bulletin: https://aretiq.ai/bulletins/2026-08-10/

    Post summary

    The bulletin announces several critical CVEs in Tencent/APIJson, Spip, and Dokploy, noting that proof‑of‑concepts and functional exploits are available, with no mention of patches or active exploitation.

    00031406
    232 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-66738 - Critical code injection in SPIP <4.4.18 via SQLite nav endpoint. Auth'd editors can RCE. CVSS 9.8. Unpatched - update/isolate now. #CVE #SPIP #infosec https://www.valtersit.com/cve/CVE-2026-66738 #CVE #Linux #infosec #infosec #cybersecurity #CVE #Linux #infosec #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #defcon #defensetech

    Post summary

    CVE‑2026‑66738 is a critical code injection flaw in SPIP versions before 4.4.18 that allows authenticated editors to achieve remote code execution via the SQLite navigation endpoint; urgent patching or isolation is recommended.

    0000052
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-66738 SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, whi… https://www.cve.org/CVERecord?id=CVE-2026-66738 ----- Traducción: CVE-2026-66738 SPI… http://infoflow.cloud`

    Post summary

    The tweet announces a code injection flaw in SPIP versions before 4.4.18 affecting SQLite installations, providing some technical detail but no PoC, exploit code, patch information, or evidence of active exploitation.

    0000030
    98 followersView on X

Explore more