SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
History

Wed, 25 Mar 2026 15:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unauthorized Administrator Assignment in SPIP CMS

Tue, 24 Mar 2026 04:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Spip
Spip spip
Vendors & Products Spip
Spip spip

Sun, 22 Mar 2026 02:30:00 +0000

Type Values Removed Values Added
Description SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
Weaknesses CWE-688
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-03-23T15:53:39.209Z

Reserved: 2026-03-22T02:03:47.214Z

Link: CVE-2026-33549

cve-icon Vulnrichment

Updated: 2026-03-23T15:16:41.626Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-22T03:16:01.237

Modified: 2026-03-23T14:31:37.267

Link: CVE-2026-33549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:46:46Z