CVE-2026-72708

LOW

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Deep dive

Full discourse1 post
  • Ambionics Security@ambionics

    🚨 Casse-Spip: pre-auth RCE on SPIP, the CMS behind thousands of French public and media sites. 🔎 Our auditor @WaykoDev found the SQLi with Claude Opus 4.8. ⚡ Chained into RCE: 4 anonymous requests, no account. ✅ Fixed in 4.4.18 (CVE-2026-72708/9/10) https://blog.lexfo.fr/casse-spip-sqli-to-rce.html

    21322172.4K
    2.0K followersView on X

Explore more