Description
The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.
Published: 2026-10-06
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Crayons plugin for SPIP before version 3.5.0 contains a missing authorization flaw; unauthenticated attackers can omit the secu_ anti‑forgery parameter in crayons_store.php, causing the dispatcher to resolve a handler that always evaluates true. This allows arbitrary modifications of editable object fields, the upload of a malicious .html skeleton, disclosure of sensitive configuration files, and the forging of a signed AJAX context so that the uploaded skeleton is executed as PHP code running under the web server account. The weakness is a classic authorization bypass (CWE-862) and results in remote code execution.

Affected Systems

The vulnerability affects installations of the SPIP Crayons Plugin earlier than version 3.5.0. Any site using an older, unpatched plugin version is potentially exposed.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity. Although no EPSS value is available, the lack of a KEV listing and the high score imply the flaw is likely to be exploited if left unpatched. Attackers do not require authentication and can reach the vulnerable code through the web interface, so the attack vector is remote, HTTP‑based. The combination of a missing anti‑forgery check, the ability to modify arbitrary fields, and the ability to execute uploaded code makes exploitation straightforward once the plugin is accessed.

Generated by OpenCVE AI on October 6, 2026 at 17:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest patch by upgrading the Crayons plugin to version 3.5.0 or later.
  • If an upgrade cannot be performed immediately, remove or disable the Crayons plugin from the site to prevent any exploitation until a secure version is installed.
  • Ensure that any anti‑forgery checks are enforced and that only authenticated users can modify editable fields, addressing the underlying authorization flaw (CWE‑862).

Generated by OpenCVE AI on October 6, 2026 at 17:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.
Title SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-06T16:16:07.042Z

Reserved: 2026-10-01T18:02:50.082Z

Link: CVE-2026-104070

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T17:17:12.213

Modified: 2026-10-06T17:17:12.213

Link: CVE-2026-104070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:00:05Z

Weaknesses