Authorization Vulnerability in Crayons Plugin for SPIP
CVE-2026-104070
9.3CRITICAL
What is CVE-2026-104070?
The Crayons plugin for SPIP prior to version 3.5.0 contains an authorization bypass vulnerability. This flaw enables unauthenticated attackers to manipulate editable object fields by omitting the required anti-forgery parameter in the crayons_store.php file. As a result, the authorization dispatcher may execute an incorrect handler, bypassing necessary modification checks. Exploiting this vulnerability could allow attackers to create a malicious .html skeleton file, access sensitive configuration files that reveal the site secret, and construct a forged ajax context to execute arbitrary PHP code with the privileges of the web server user.
Affected Version(s)
SPIP Crayons Plugin 0 < 3.5.0
