Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-104070: SPIP Crayons plugin enables remote code execution
CVE-2026-104070 · published 3 days ago
Summary
The Crayons add‑on for the SPIP content system (versions before 3.5.0) lets anyone on the internet change content fields without logging in. By skipping a security check, an attacker can upload a malicious file, view hidden configuration data, and run their own PHP code on your server. Update the plugin to version 3.5.0 or later, or remove it until you can apply the fix.
What to do
- Update spip spip crayons plugin to version 3.5.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| spip | spip crayons plugin | < 3.5.0 |
Original advisory text
SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE
The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-862Missing Authorization
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta