Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104070— SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE

Quick assessment

Affected
SPIP SPIP Crayons Plugin
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SPIP 3.5.0 版本之前的 Crayons 插件存在一个授权缺失漏洞,未经身份验证的攻击者可以通过在 crayons_store.php 中省略 secu_(反伪造)参数,修改任意可编辑对象的字段,导致授权调度器无条件解析一个“始终为真”的处理程序,而不是执行正确的修改检查。攻击者可以利用此漏洞链式攻击:写入恶意的 .html 模板文件、泄露包含站点密钥的敏感配置文件,并伪造已签名的 AJAX 上下文以执行上传的模板,从而实现以 Web 服务器用户身份执行任意 PHP 代码。

CVSS 9.8 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104070

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE
Source: CVE Program / CVE List V5
Vulnerability Description
The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SPIP SPIP Crayons Plugin 0 ~ 3.5.0 -

II. Public POCs for CVE-2026-104070

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104070

请登录查看更多情报信息。

Other References for CVE-2026-104070 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104070

No comments yet


Leave a comment