---
id: CVE-2026-104070
title: >-
  The Crayons plugin for SPIP before 3.5.0 contains a missing authorization
  vulnerability that allows unauthenticated attackers to modify arbitrary
  editable object fields by omitting the secu_ anti-forgery parameter in
  crayons_store.php, c…
summary: >-
  The Crayons plugin for SPIP before 3.5.0 contains a missing authorization
  vulnerability that allows unauthenticated attackers to modify arbitrary
  editable object fields by omitting the secu_ anti-forgery parameter in
  crayons_store.php, c…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-862
vendor: SPIP
product: SPIP Crayons Plugin
affected:
  - crayons_plugin < 3.5.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T17:17:12.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104070'
references:
  - url: >-
      https://blog.spip.net/Mises-a-jour-de-securite-critique-plugins-Crayons-et-Simplog.html?lang=fr
    label: disclosure@vulncheck.com
  - url: 'https://plugins.spip.net/crayons.html?lang=fr'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/spip-crayons-plugin-authorization-bypass-rce
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T17:09:22.200Z'
---

## Overview

The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
