{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/crayons-plugin--3.5.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:spip:crayons_plugin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-104070"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Crayons plugin (\u003c 3.5.0)"],"_cs_severities":["critical"],"_cs_tags":["web-application","rce","cve-2026-104070"],"_cs_type":"advisory","_cs_vendors":["SPIP"],"content_html":"\u003cp\u003eThe Crayons plugin for SPIP, a content management system, contains a critical missing authorization vulnerability tracked as CVE-2026-104070. The vulnerability resides in 'crayons_store.php' and affects all versions prior to 3.5.0. By omitting the 'secu_' anti-forgery parameter, an unauthenticated attacker can force the authorization dispatcher to resolve an unconditionally-true handler. This bypass allows the attacker to modify arbitrary editable object fields within the SPIP installation. This vulnerability acts as a primitive for an escalation chain: attackers can use this access to write malicious '.html' skeleton files to the server, read site configuration files to extract the site secret, and ultimately sign a forged AJAX context to execute the uploaded malicious code, resulting in arbitrary PHP execution as the web-server user.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends a crafted HTTP POST request to 'crayons_store.php' omitting the 'secu_' parameter.\u003c/li\u003e\n\u003cli\u003eThe application's authorization dispatcher incorrectly resolves to an 'unconditionally-true' handler.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the authorization bypass to perform unauthorized modification of site objects.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes the modification capability to write a malicious '.html' skeleton file to a directory accessible by the web server.\u003c/li\u003e\n\u003cli\u003eAttacker targets sensitive configuration files to read and disclose the site secret key.\u003c/li\u003e\n\u003cli\u003eAttacker uses the disclosed site secret to sign a forged AJAX request.\u003c/li\u003e\n\u003cli\u003eAttacker executes the signed request to trigger the previously uploaded malicious skeleton file.\u003c/li\u003e\n\u003cli\u003ePHP code within the malicious skeleton is executed, granting the attacker arbitrary code execution privileges.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-104070 grants an unauthenticated attacker full remote code execution capabilities on the host server. This allows for total system compromise, data exfiltration, and lateral movement within the target network. Given the nature of SPIP as a CMS, this vulnerability poses a high risk to all public-facing websites utilizing the Crayons plugin in versions prior to 3.5.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Crayons plugin for SPIP to version 3.5.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious POST requests to 'crayons_store.php' that lack the 'secu_' parameter or exhibit unconventional 'crayons' action patterns.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized file creation events in directories where SPIP stores skeleton files (typically '/squelettes/').\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-06T18:57:16Z","date_published":"2026-10-06T18:57:16Z","id":"https://feed.craftedsignal.io/briefs/2026-10-spip-crayons-auth-bypass/","summary":"The Crayons plugin for SPIP before 3.5.0 contains a missing authorization flaw in crayons_store.php that allows unauthenticated attackers to modify arbitrary objects, leading to remote code execution.","title":"Unauthenticated RCE in SPIP Crayons Plugin via CVE-2026-104070","url":"https://feed.craftedsignal.io/briefs/2026-10-spip-crayons-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Crayons Plugin (\u003c 3.5.0)","version":"https://jsonfeed.org/version/1.1"}