CVE-2026-104070: SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE

Published Oct 6, 2026
·
Updated

The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu anti-forgery parameter in crayonsstore.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.

Affected Software

1 affected component
Spip Crayons Plugin<3.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SPIP Crayons Plugin to a version that resolves this vulnerability.

    Fixed in 3.5.0

Event History

Oct 6, 2026
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Does exploitation require an authenticated SPIP account or user interaction?

No. The vulnerability is exploitable remotely by an unauthenticated attacker and requires neither privileges nor user interaction.

2

What access does successful exploitation provide?

An attacker can ultimately achieve arbitrary PHP code execution as the web-server user. The described chain includes modifying editable fields, writing a malicious .html skeleton, disclosing configuration containing the site secret, and forging a signed AJAX context.

3

Which configurations are affected?

The issue affects SPIP installations using the Crayons plugin before version 3.5.0. The vulnerable authorization path is triggered by omitting the secu_ anti-forgery parameter in crayons_store.php.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203