Sceawere

Vulnerability Detail

CVE-2026-104070UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Crayons Plugin Missing Authorization RCE

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
8h ago
Vendor
SPIP
Product
SPIP Crayons Plugin
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-06T17:17:12.213Z",
  "pubdate": "2026-10-06T17:17:12.213Z",
  "executiveSummary": "The Crayons plugin for SPIP, in versions prior to 3.5.0, suffers from a critical missing authorization vulnerability leading to unauthenticated arbitrary object modification and potential remote code execution (RCE).\nThe vulnerability originates from improper validation logic within the 'crayons_store.php' file, specifically regarding the 'secu_' anti-forgery parameter.\nBy omitting this mandatory parameter, an unauthenticated attacker can bypass authorization dispatching, forcing the application to execute an unconditionally-true handler.\nThis flaw grants attackers the ability to modify arbitrary editable object fields. The impact is severe, as the vulnerability can be chained to write malicious files, disclose sensitive site secrets, and forge signed ajax contexts.\nSuccessful exploitation allows an unauthenticated attacker to achieve arbitrary PHP code execution under the privileges of the web-server process, posing a total compromise risk to the host environment.",
  "technicalDetails": "The root cause of this vulnerability lies in the authorization dispatching mechanism implemented in 'crayons_store.php'. The plugin is designed to process AJAX-based field edits using a security token mechanism denoted by the 'secu_' parameter, which is intended to prevent cross-site request forgery and ensure that only authorized users can modify object content.\nWhen the 'secu_' parameter is omitted from the request, the authorization dispatcher fails to perform a negative validation. Instead, the logic inadvertently resolves to an unconditionally-true handler. This failure allows unauthorized requests to pass through the modification check as if they were legitimate and authorized actions.\nThe attack flow begins with the manipulation of object fields via the Crayons interface. By crafting a request that omits the security token, an attacker can bypass the intended authorization constraints and force the application to overwrite critical system data.\nThe exploitation chain is multi-stage and highly impactful. First, the attacker uses the missing authorization vulnerability to modify fields that control site structure or file content. By targeting specific editable objects, the attacker writes a malicious .html skeleton file to the server's filesystem.\nSecond, the attacker leverages the unauthorized access to disclose sensitive configuration files that contain the site's secret key. With the secret key in possession, the attacker can sign requests or forge an AJAX context that the SPIP application accepts as trusted.\nThird, the attacker uses the forged, signed AJAX context to execute the previously uploaded malicious .html skeleton. Because SPIP evaluates these skeleton files as PHP, this leads directly to arbitrary PHP code execution. The resulting execution occurs with the same permissions as the web-server user, enabling full system interaction, data exfiltration, or further lateral movement within the network.\nThe vulnerability is present in all versions of the Crayons plugin for SPIP prior to 3.5.0. It is network-exploitable and does not require pre-existing authentication or elevated privileges, representing a significant security risk for any deployment using this plugin."
}
CVE-2026-104070: Crayons Plugin Missing Authorization RCE (CRITICAL Severity, CVSS: 9.8) | Sceawere