HarborGuard / CVE
Back to search
HIGHCVE-2026-22205Published Modified CNA VulnCheck

CVE-2026-22205: SPIP < 4.4.10 Authentication Bypass via PHP Type Juggling

SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive internal data.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
4.4.10
Affected Products
1

Fix available

4.4.10
Patch commits
Affected packages
  • SPIP / SPIP
    < 4.4.10 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE-2026-22205: SPIP < 4.4.10 Authentication Bypass via PHP Type Juggling | HarborGuard CVE