LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-8430 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: May 12, 2026

Published: May 12, 2026Updated: May 12, 2026Remote Exploitable

Overview

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability through specific nginx configuration scenarios to achieve code execution, and this issue is not mitigated by the SPIP security screen.

Severity & Score

Severity: High
CVSS Score: 8.1

Details

CVE ID
CVE-2026-8430
Severity
High
CVSS Score
8.1
Status
new

CWE

  • CWE-94

CVSS Metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H