CVE-2026-8429 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: May 12, 2026
Published: May 12, 2026Updated: May 12, 2026Remote Exploitable
Overview
SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability to achieve code execution that bypasses the SPIP security screen protections.
Severity & Score
Severity: High
CVSS Score: 8.8
References
Related Resources
Details
- CVE ID
- CVE-2026-8429
- Severity
- High
- CVSS Score
- 8.8
- Status
- new
CWE
- CWE-94
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H