CRITICAL
9.8 CVE-2026-104070 Published 6 Oct 2026
SPIP Crayons Plugin Missing Authorization Leads to Remote Code Execution
Worried this affects your website?
The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that lets unauthenticated attackers modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php. This causes the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check.
Attackers can chain the flaw to:
- Write a malicious .html skeleton file
- Disclose sensitive configuration files containing the site secret
- Forge a signed ajax context to execute the uploaded skeleton
This chain achieves arbitrary PHP code execution as the web-server user.
Reference: CVE-2026-104070 on NVD
← Back to Security News