CVE-2026-33549

SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
Configurations

Configuration 1 (hide)

cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-22 03:16

Updated : 2026-06-17 10:37


NVD link : CVE-2026-33549

Mitre link : CVE-2026-33549

CVE.ORG link : CVE-2026-33549


JSON object : View

Products Affected

spip

  • spip
CWE
CWE-688

Function Call With Incorrect Variable or Reference as Argument