Unauthenticated RCE in SPIP Crayons Plugin via CVE-2026-104070
The Crayons plugin for SPIP before 3.5.0 contains a missing authorization flaw in crayons_store.php that allows unauthenticated attackers to modify arbitrary objects, leading to remote code execution.
CVE search metadata
CVE search record: CVE-2026-104070. Severity: critical. CVSS: 9.8. KEV: no. Product: Crayons plugin (< 3.5.0). Brief: Unauthenticated RCE in SPIP Crayons Plugin via CVE-2026-104070. Brief link: https://feed.craftedsignal.io/briefs/2026-10-spip-crayons-auth-bypass/
The Crayons plugin for SPIP, a content management system, contains a critical missing authorization vulnerability tracked as CVE-2026-104070. The vulnerability resides in 'crayons_store.php' and affects all versions prior to 3.5.0. By omitting the 'secu_' anti-forgery parameter, an unauthenticated attacker can force the authorization dispatcher to resolve an unconditionally-true handler. This bypass allows the attacker to modify arbitrary editable object fields within the SPIP installation. This vulnerability acts as a primitive for an escalation chain: attackers can use this access to write malicious '.html' skeleton files to the server, read site configuration files to extract the site secret, and ultimately sign a forged AJAX context to execute the uploaded malicious code, resulting in arbitrary PHP execution as the web-server user.
Attack Chain
- Attacker sends a crafted HTTP POST request to 'crayons_store.php' omitting the 'secu_' parameter.
- The application's authorization dispatcher incorrectly resolves to an 'unconditionally-true' handler.
- Attacker leverages the authorization bypass to perform unauthorized modification of site objects.
- Attacker utilizes the modification capability to write a malicious '.html' skeleton file to a directory accessible by the web server.
- Attacker targets sensitive configuration files to read and disclose the site secret key.
- Attacker uses the disclosed site secret to sign a forged AJAX request.
- Attacker executes the signed request to trigger the previously uploaded malicious skeleton file.
- PHP code within the malicious skeleton is executed, granting the attacker arbitrary code execution privileges.
Impact
Successful exploitation of CVE-2026-104070 grants an unauthenticated attacker full remote code execution capabilities on the host server. This allows for total system compromise, data exfiltration, and lateral movement within the target network. Given the nature of SPIP as a CMS, this vulnerability poses a high risk to all public-facing websites utilizing the Crayons plugin in versions prior to 3.5.0.
Recommendation
- Upgrade the Crayons plugin for SPIP to version 3.5.0 or later immediately.
- Audit web server logs for suspicious POST requests to 'crayons_store.php' that lack the 'secu_' parameter or exhibit unconventional 'crayons' action patterns.
- Monitor for unauthorized file creation events in directories where SPIP stores skeleton files (typically '/squelettes/').
Immediate actions
Upgrade Crayons plugin to 3.5.0 or later.
Mitigations
Upgrade Crayons plugin to 3.5.0.
CVE-2026-104070