A missing authorization check in the Crayons plugin for SPIP before 3.5.0 lets unauthenticated attackers modify editable object fields, and they can chain that flaw into arbitrary PHP code execution as the web-server user.
What Is It
CVE-2026-104070 is a missing authorization vulnerability (CWE-862) in crayons_store.php, part of the SPIP Crayons plugin. If an attacker leaves out the secu_ anti-forgery parameter from a request, the plugin's authorization dispatcher resolves an unconditionally-true handler instead of running the proper modification check. As a result, unauthenticated attackers can modify arbitrary editable object fields.
According to the disclosure, the flaw can be chained into full code execution:
- Write a malicious
.htmlskeleton file. - Disclose sensitive configuration files that contain the site secret.
- Use that secret to forge a signed ajax context that executes the uploaded skeleton.
The result is arbitrary PHP code execution as the web-server user.
Why It Matters
VulnCheck, the CVE numbering authority, rates this flaw 9.8 CRITICAL under CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and 9.3 CRITICAL under CVSS 4.0. The attack works over the network with low complexity. It needs no privileges and no user interaction. A successful attack fully compromises confidentiality, integrity and availability on the affected host.
Exposing the site secret also widens the impact beyond code execution, because that secret is what allows signed ajax contexts to be forged.
In the supplied data, this CVE has no CISA KEV entry, so CISA has not confirmed active exploitation. NVD lists the record as "Awaiting Analysis," published 2026-10-06.
What's Vulnerable
- Vendor: SPIP
- Product: SPIP Crayons Plugin
- Affected versions: all versions before 3.5.0 (semver range 0 to <3.5.0)
The affected-version data does not list any specific CPEs.
Patch Status
The plugin is fixed in Crayons 3.5.0. Administrators running SPIP with the Crayons plugin should upgrade to version 3.5.0 or later. SPIP has published a critical security update notice covering the Crayons and Simplog plugins (linked below). Because the exploit chain can expose the site secret, sites that ran a vulnerable version should treat that secret as possibly compromised. Since this CVE is not in KEV, there is no CISA-mandated remediation deadline.