CVE-2026-77806
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code...
- Published
- Aug 21, 2026
- Updated
- Aug 21, 2026
- Assigning CNA
- mitre
- Evidence observed
- Aug 25, 2026
Primary CVSS
cvelist · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
Sources
http/cves/2026/CVE-2026-77806.yaml
Nuclei TemplatesDeclared conditions
- network: http($.protocol_keys)
- verification: dsl($.matchers[*].type)
- CVE-2026-77806Exploit
Detection and exploitation scripts for CVE-2026-77806, providing proof-of-concept code for security testing and vulnerability verification.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.