CVE-2026-72708 Overview
CVE-2026-72708 is an unauthenticated blind SQL injection vulnerability in SPIP versions before 4.4.18. The flaw resides in SPIP's SQL escaping layer, which fails to sanitize date-type column values when input matches a word character followed by an open parenthesis. Attackers can reach the vulnerable code path through the always-present sitemap.xml.html template using the annee parameter. Exploitation works across MySQL, SQLite, and PostgreSQL backends, allowing unauthenticated extraction of arbitrary database content. The extracted data includes the alea_ephemere secret used to sign SPIP action nonces, enabling further attack chains toward remote code execution.
Critical Impact
Unauthenticated attackers can extract arbitrary database contents, including cryptographic secrets that sign SPIP action nonces, enabling escalation to remote code execution.
Affected Products
- SPIP content management system versions prior to 4.4.18
- Deployments backed by MySQL, SQLite, or PostgreSQL databases
- Any SPIP site exposing the default sitemap.xml.html template
Discovery Timeline
- 2026-09-11 - CVE-2026-72708 published to NVD
- 2026-09-15 - Last updated in NVD database
Technical Details for CVE-2026-72708
Vulnerability Analysis
The vulnerability is a classic SQL injection [CWE-89] rooted in SPIP's centralized SQL escaping layer. SPIP treats date-typed column values with a specialized escaping code path. That code path assumes input matching the pattern of a word character followed by an open parenthesis represents a safe SQL function call and skips quoting. An attacker who crafts input matching this pattern can pass raw SQL fragments into the composed query.
The sitemap.xml.html template is always available in a default SPIP installation and accepts an annee (year) criterion. This criterion is compiled against a date column, routing attacker input through the flawed escaping branch. Because the backend is queried directly, blind extraction is achievable through time-based delays or boolean conditions across MySQL, SQLite, and PostgreSQL.
Successful extraction of the alea_ephemere secret allows attackers to forge valid action nonces. Public analysis by Lexfo demonstrates chaining this primitive to authenticated actions, ultimately reaching remote code execution.
Root Cause
The escaping function inspects the value's shape rather than the trust boundary of its source. When a value matches the regular expression pattern for a word character followed by (, SPIP presumes the input is a SQL function invocation and forwards it unquoted. Attacker-controlled request parameters can trivially satisfy that pattern, so untrusted data bypasses escaping entirely for any date-typed column comparison.
Attack Vector
Exploitation requires only a network-reachable SPIP instance. The attacker issues an unauthenticated HTTP request to the sitemap endpoint with an annee parameter carrying a payload shaped like IF(...) or an equivalent function call. The value flows into the compiled SQL for the date criterion without quoting, and the injected expression is evaluated by the database. Time delays or conditional responses reveal one bit of data per request, enabling full database extraction.
A representative attack targets the sitemap endpoint with an annee value beginning with a function-like token, causing the database to conditionally sleep or alter output based on the value of a queried secret. See the Lexfo SQLi to RCE Analysis and the VulnCheck Unauthenticated SQL Injection Advisory for concrete payload structure.
Detection Methods for CVE-2026-72708
Indicators of Compromise
- HTTP requests to sitemap.xml.html or spip.php?page=sitemap.xml containing an annee parameter whose value starts with a word character immediately followed by (
- Requests where the annee value contains SQL keywords such as IF, CASE, SLEEP, PG_SLEEP, RANDOMBLOB, or SUBSTRING
- Repeated sitemap requests from a single source with varying annee values, indicating boolean or time-based enumeration
- Database query logs showing unusually long execution times on queries filtered by year on SPIP tables
Detection Strategies
- Deploy a web application firewall rule that blocks or alerts on annee parameter values not matching a strict numeric year pattern such as ^[0-9]{4}$
- Correlate spikes in requests to sitemap templates with database slow-query log entries referencing SPIP tables
- Hunt for outbound access patterns from the SPIP web account following sitemap requests, which may indicate post-exploitation activity
Monitoring Recommendations
- Enable verbose access logging on all SPIP endpoints and forward logs to a centralized analytics platform for retention and query
- Monitor SPIP database user query volume and latency for statistical anomalies aligned with public request bursts
- Alert on file writes under SPIP cache and template directories following suspicious sitemap traffic, which may indicate nonce forgery leading to code execution
How to Mitigate CVE-2026-72708
Immediate Actions Required
- Upgrade SPIP to version 4.4.18 or later on all affected instances without delay
- Rotate the alea_ephemere secret and any other secrets stored in the SPIP database after patching, since prior extraction cannot be ruled out
- Audit SPIP administrative accounts and recent action logs for unauthorized changes indicative of nonce-based follow-on exploitation
- Reset database credentials used by SPIP if the site was internet-exposed prior to patching
Patch Information
The SPIP project addressed CVE-2026-72708 in release 4.4.18. The fix hardens the SQL escaping layer so that date-typed values from untrusted input are quoted rather than treated as SQL function calls. Refer to the SPIP Security Update 4.4.18 announcement for release notes and upgrade instructions.
Workarounds
- Deploy a reverse proxy or WAF rule that enforces a strict numeric format for the annee parameter on requests reaching SPIP
- Restrict access to sitemap.xml.html and related sitemap templates using network ACLs or authentication where operationally feasible
- Apply least-privilege database permissions to the SPIP database user so that even successful injection cannot access unrelated schemas
# Example WAF rule enforcing a numeric-only annee parameter (ModSecurity)
SecRule ARGS:annee "!@rx ^[0-9]{4}$" \
"id:1072708,phase:2,deny,status:400,\
msg:'CVE-2026-72708 SPIP sitemap annee parameter blocked'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
