CVE-2026-104070: SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE
The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu anti-forgery parameter in crayonsstore.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SPIP Crayons Pluginto a version that resolves this vulnerability.Fixed in 3.5.0
Event History
Frequently Asked Questions
Does exploitation require an authenticated SPIP account or user interaction?
No. The vulnerability is exploitable remotely by an unauthenticated attacker and requires neither privileges nor user interaction.
What access does successful exploitation provide?
An attacker can ultimately achieve arbitrary PHP code execution as the web-server user. The described chain includes modifying editable fields, writing a malicious .html skeleton, disclosing configuration containing the site secret, and forging a signed AJAX context.
Which configurations are affected?
The issue affects SPIP installations using the Crayons plugin before version 3.5.0. The vulnerable authorization path is triggered by omitting the secu_ anti-forgery parameter in crayons_store.php.