CVE-2026-22205

Source
https://cve.org/CVERecord?id=CVE-2026-22205
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22205.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-22205
Downstream
Published
2026-02-26T21:28:52.217Z
Modified
2026-03-15T22:51:50.541684Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive internal data.

References

Affected packages

Git / git.spip.net/spip/spip

Affected ranges

Type
GIT
Repo
https://git.spip.net/spip/spip
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
020fb398ca507b9d9dce6d3b25908b340998a17b
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.4.10"
        }
    ]
}

Affected versions

4.*
4.4.0
4.4.0-beta
4.4.0-beta2
4.4.0-beta3
4.4.0-beta4
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
v3.*
v3.0.0-beta.2
v3.1.0-alpha
v3.1.0-beta
v4.*
v4.0.0-alpha
v4.0.0-beta
v4.2.0
v4.2.0-alpha
v4.2.0-alpha2
v4.2.1
v4.2.10
v4.2.11
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0-alpha
v4.3.0-alpha2
v4.3.0-beta

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22205.json"