Authorization Vulnerability in Crayons Plugin for SPIP
CVE-2026-104070

9.3CRITICAL

Key Information:

Vendor

Spip

Vendor
CVE Published:
6 October 2026

What is CVE-2026-104070?

The Crayons plugin for SPIP prior to version 3.5.0 contains an authorization bypass vulnerability. This flaw enables unauthenticated attackers to manipulate editable object fields by omitting the required anti-forgery parameter in the crayons_store.php file. As a result, the authorization dispatcher may execute an incorrect handler, bypassing necessary modification checks. Exploiting this vulnerability could allow attackers to create a malicious .html skeleton file, access sensitive configuration files that reveal the site secret, and construct a forged ajax context to execute arbitrary PHP code with the privileges of the web server user.

Affected Version(s)

SPIP Crayons Plugin 0 < 3.5.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thomas Sanzey
VulnCheck
.