CVE-2026-22205

SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive internal data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-26 21:28

Updated : 2026-03-02 16:08


NVD link : CVE-2026-22205

Mitre link : CVE-2026-22205

CVE.ORG link : CVE-2026-22205


JSON object : View

Products Affected

spip

  • spip
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel