CVE-2026-33549
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
- EPSS probability
- 0.24%
- CWE
- CWE-688
- Published
- 2026-03-22
- Last modified
- 2026-04-02
Affected products
- SPIP SPIP
Weakness type
Related vulnerabilities
- CVE-2026-76878 — In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects...
- CVE-2021-33713 — A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing...