[Git][security-tracker-team/security-tracker][master] CVE-2026-77806/spip assigned

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 20:36:05 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4368a567 by Salvatore Bonaccorso at 2026-08-21T21:35:20+02:00
CVE-2026-77806/spip assigned

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -12,8 +12,6 @@ CVE-2026-77814 (is_path_trusted in scripts/iib/api.py compares the requested pat
 	TODO: check
 CVE-2026-77812 (DJI drones transmit DUML (DJI Universal Markup Language) protocol mess ...)
 	NOT-FOR-US: DJI
-CVE-2026-77806 (SPIP before 4.4.21 allows unauthenticated remote attackers to execute  ...)
-	TODO: check
 CVE-2026-77795 (A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2.  ...)
 	TODO: check
 CVE-2026-77780 (Authorization Bypass Through User-Controlled Key in the transaction sa ...)
@@ -17868,9 +17866,8 @@ CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0
 	NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014
 CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4. ...)
 	NOT-FOR-US: Joomla
-CVE-2026-XXXX [RCE fixed in 4.4.21]
+CVE-2026-77806 [RCE fixed in 4.4.21]
 	- spip 4.4.21+dfsg-1
-	[trixie] - spip 4.4.21+dfsg-0+deb13u1
 	NOTE: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html
 CVE-2026-77647 (SPIP before 4.4.20 allows unauthenticated remote attackers to execute  ...)
 	{DSA-6448-1}


=====================================
data/DSA/list
=====================================
@@ -1,4 +1,5 @@
 [21 Aug 2026] DSA-6456-1 spip - security update
+	{CVE-2026-77806}
 	[trixie] - spip 4.4.21+dfsg-0+deb13u1
 [20 Aug 2026] DSA-6455-1 chromium - security update
 	{CVE-2026-76033 CVE-2026-76034 CVE-2026-76035 CVE-2026-76036 CVE-2026-76037 CVE-2026-76038 CVE-2026-76039 CVE-2026-76040 CVE-2026-76041 CVE-2026-76042 CVE-2026-76043 CVE-2026-76044 CVE-2026-76045 CVE-2026-76046 CVE-2026-76047}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4368a567858cf4b54e9a255f362d2549518504b1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4368a567858cf4b54e9a255f362d2549518504b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/985a2778/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list