CVE-2026-22205 - SPIP < 4.4.10 Authentication Bypass via PHP Type Juggling

CVE-2026-22205 - SPIP < 4.4.10 Authentication Bypass via PHP Type Juggling

CVE ID : CVE-2026-22205 Published : Feb. 26, 2026, 9:28 p.m. | 37 minutes ago Description : SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive internal data. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Feb. 26, 2026
Affected Product: PHP
Impact: authentication bypass