CVE-2026-104070
Received Received - Intake

Crayons Plugin Missing Authorization Leading to PHP Code Execution

Vulnerability report for CVE-2026-104070, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulnCheck

Description

The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
SPIP SPIP Crayons Plugin 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Crayons plugin for SPIP before version 3.5.0 has a missing authorization vulnerability. Unauthenticated attackers can exploit this by omitting a security parameter in a specific file, bypassing modification checks. This allows them to alter editable object fields and potentially upload malicious files, leading to further exploitation.

Detection Guidance

Check for unauthorized modifications to SPIP editable object fields by inspecting crayons_store.php requests missing the secu_ anti-forgery parameter. Look for unexpected .html skeleton files or suspicious configuration file disclosures.

Impact Analysis

This vulnerability can allow attackers to execute arbitrary PHP code on your server, access sensitive configuration files, and potentially take full control of your website. It may lead to data breaches, defacement, or further compromise of your system and user data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations may face legal penalties, fines, and reputational damage due to non-compliance resulting from this security flaw.

Mitigation Strategies

Update the Crayons plugin for SPIP to version 3.5.0 or later immediately. If an update is not available, disable the plugin until a patch is released. Review server logs for signs of exploitation and remove any unauthorized files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104070. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart