
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22206 is a SQL injection vulnerability in SPIP (a popular open-source CMS) affecting all versions prior to 4.4.10. It allows authenticated low-privilege users to execute arbitrary SQL queries via union-based injection techniques, and can be chained with PHP tag processing to achieve remote code execution (RCE) on the server. The CVE was published on February 26, 2026, and assigned by VulnCheck. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (VulnCheck Advisory, SPIP Blog).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), rooted in insufficient sanitization of user-supplied input in SPIP's database query layer. An authenticated attacker with low privileges can craft union-based SQL injection payloads to manipulate database queries and extract or modify data. Critically, the flaw can be combined with SPIP's PHP tag processing mechanism to escalate from SQL injection to full remote code execution on the server. The attack requires no user interaction and is exploitable over the network with low complexity (VulnCheck Advisory, SPIP Git).
Successful exploitation grants an attacker complete control over the affected SPIP instance, with high impact to confidentiality, integrity, and availability. An attacker can extract sensitive data from the database (including user credentials and private content), modify or delete data, and execute arbitrary commands on the underlying server via the PHP tag processing chain. This could enable full server compromise, lateral movement within the hosting environment, and potential takeover of the web application and its infrastructure (VulnCheck Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability is detected by Nessus (plugins 300156, 300870) and Qualys (6274297), indicating scanner coverage. The EPSS score is approximately 0.0016 (0.16%), reflecting a currently low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.
UNION, SELECT, FROM, or encoded variants; unexpected outbound connections from the web server to external IPs./tmp or writable web directories.bash, curl, wget, python, nc); unexpected cron jobs or scheduled tasks created under the web server user account.The primary remediation is to upgrade SPIP to version 4.4.10 or later, which contains the fix for this vulnerability (SPIP Blog). A Debian security advisory (DSA-6155-1) has also been issued for Debian users (Debian Advisory). As interim mitigations, administrators should restrict the number of authenticated low-privilege users, implement a web application firewall (WAF) to detect and block SQL injection attempts, and monitor database query logs for anomalous activity. Disabling PHP tag processing in SPIP configuration, if operationally feasible, would reduce the RCE escalation risk.
The vulnerability received coverage from security aggregators and community platforms including Bluesky and Mastodon shortly after disclosure, with posts from accounts such as @thehackerwire highlighting the SQL injection to RCE chain (Bluesky). A technical blog post was published by Infinitsec detailing the exploitation mechanics (Infinitsec Blog). Debian issued a security advisory (DSA-6155-1) covering the affected SPIP package, and scanner vendors Tenable and Qualys rapidly added detection plugins (Tenable).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."