CRITICAL 9.8 CVE-2026-104070 Published 6 Oct 2026

SPIP Crayons Plugin Missing Authorization Leads to Remote Code Execution

Worried this affects your website?

The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that lets unauthenticated attackers modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php. This causes the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check.

Attackers can chain the flaw to:

  • Write a malicious .html skeleton file
  • Disclose sensitive configuration files containing the site secret
  • Forge a signed ajax context to execute the uploaded skeleton

This chain achieves arbitrary PHP code execution as the web-server user.

Reference: CVE-2026-104070 on NVD

← Back to Security News