9.2
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition requiring prior access or another vulnerability) can trigger arbitrary object instantiation and potentially achieve code execution. The use of serialized data in these components has been deprecated and will be removed in SPIP 5. This vulnerability is not mitigated by the SPIP security screen.
AI Analysis
Insecure Deserialization vulnerability in SPIP before 4.4.9, allowing arbitrary object instantiation and potentially code execution through malicious serialized content.
Basic Information
ID
CVE-2026-27475
Source
VulnCheck
Published
Feb 19, 2026 at 18:39
Affected Product
Vendor
SPIP
Product
SPIP
Version
4.4.0
Affected Versions
SPIP SPIP 4.4.0
CWE Classification
AI Assessment
AI Score
9.2 / 10
AI Severity
Critical
Vendor
SPIP
Product
SPIP
Version
4.4.0