Cyber & AI intelligence
Wasteland.
Briefs indexed3048
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-104070 2026-10-06

Critical Unauthenticated RCE Chain in SPIP Crayons Plugin (CVE-2026-104070)

"A missing authorization check in the Crayons plugin for SPIP before 3.5.0 lets unauthenticated attackers modify editable object fields, and they can chain that flaw into arbitrary PHP code execution as the web-server…"

A missing authorization check in the Crayons plugin for SPIP before 3.5.0 lets unauthenticated attackers modify editable object fields, and they can chain that flaw into arbitrary PHP code execution as the web-server user.

What Is It

CVE-2026-104070 is a missing authorization vulnerability (CWE-862) in crayons_store.php, part of the SPIP Crayons plugin. If an attacker leaves out the secu_ anti-forgery parameter from a request, the plugin's authorization dispatcher resolves an unconditionally-true handler instead of running the proper modification check. As a result, unauthenticated attackers can modify arbitrary editable object fields.

According to the disclosure, the flaw can be chained into full code execution:

  1. Write a malicious .html skeleton file.
  2. Disclose sensitive configuration files that contain the site secret.
  3. Use that secret to forge a signed ajax context that executes the uploaded skeleton.

The result is arbitrary PHP code execution as the web-server user.

Why It Matters

VulnCheck, the CVE numbering authority, rates this flaw 9.8 CRITICAL under CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and 9.3 CRITICAL under CVSS 4.0. The attack works over the network with low complexity. It needs no privileges and no user interaction. A successful attack fully compromises confidentiality, integrity and availability on the affected host.

Exposing the site secret also widens the impact beyond code execution, because that secret is what allows signed ajax contexts to be forged.

In the supplied data, this CVE has no CISA KEV entry, so CISA has not confirmed active exploitation. NVD lists the record as "Awaiting Analysis," published 2026-10-06.

What's Vulnerable

The affected-version data does not list any specific CPEs.

Patch Status

The plugin is fixed in Crayons 3.5.0. Administrators running SPIP with the Crayons plugin should upgrade to version 3.5.0 or later. SPIP has published a critical security update notice covering the Crayons and Simplog plugins (linked below). Because the exploit chain can expose the site secret, sites that ran a vulnerable version should treat that secret as possibly compromised. Since this CVE is not in KEV, there is no CISA-mandated remediation deadline.

Sources