External risk intelligence

SPIP Crayons Plugin Authorization Bypass Leading to Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-104070

SPIP is a content management system designed to power public-facing websites. Plugins for such systems, including the vulnerable Crayons plugin, are typically installed on web servers that are directly exposed to the internet to facilitate site management and dynamic content generation, making the affected interface a common part of an internet-facing web application deployment.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in the Crayons plugin for SPIP, a content management system. The flaw allows unauthenticated attackers to execute arbitrary code on the web server, potentially leading to the disclosure of sensitive information and full system compromise. The main concern is confirming relevance and exposure within affected SPIP installations.

  • Unauthenticated attackers can execute code on servers.
  • Critical code execution risk affecting public websites.
  • Assess exposure for SPIP sites using the plugin.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a request to the Crayons plugin that lacks a specific security parameter. This allows them to bypass authorization checks, leading to potential code execution on the affected web server.

  • No authentication needed.
  • Missing security parameter in request.
  • Arbitrary code execution possible.

Live Threat

Current exploitation, exposure, and threat context

The Crayons plugin for SPIP, when vulnerable, could allow unauthenticated attackers to execute arbitrary PHP code on the web server. This is achieved by bypassing authorization checks to modify sensitive fields, enabling the upload and execution of a malicious HTML skeleton file. The affected system could be compromised to run code as the web server user, potentially impacting the integrity and availability of the website and its underlying server.

  • Arbitrary PHP code execution.
  • Unauthenticated access to modify fields.
  • Compromise of web server.

Operational Fix

Recommended remediation, mitigation, and detection steps

The SPIP platform's Crayons plugin is likely managed by the web application or platform team responsible for the SPIP installation. The first practical step is to identify all SPIP instances, determine if the Crayons plugin is active, and assess exposure and criticality, especially for internet-facing sites. Coordination with the vendor or plugin provider may be necessary for remediation.

  • Application or platform teams should own this.
  • Verify Crayons plugin activation and exposure.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Crayons plugin for SPIP?

Crayons is a specialized add-on for SPIP, a popular open-source content management system. It is commonly used by site administrators to enable inline, dynamic editing of web content directly from the front end, streamlining the management of articles and site elements without needing to access the back-end dashboard.

What does CWE-862 mean for CVE-2026-104070?

CWE-862 refers to a missing authorization weakness. In the context of this CVE, it means the plugin fails to verify that the person requesting a change has the proper permissions. Because this check is omitted, the system erroneously assumes the action is authorized, allowing anyone to modify sensitive data or execute restricted functions.

How can an attacker trigger this vulnerability?

An attacker can exploit this by sending a crafted request to the plugin that deliberately excludes the 'secu_' anti-forgery parameter. When this parameter is absent, the plugin’s authorization logic defaults to an unconditionally-true state. Note that this bug is not triggered if the correct, valid security token is present in the request.

Why is this a high-priority risk for my web server?

Halo Surface Signal indicates that SPIP installations are typically deployed as public-facing websites. Because the Crayons plugin is designed to interface directly with site content, it is often exposed to the internet. This accessibility means unauthenticated attackers do not need internal network access to reach and exploit the vulnerable code.

Do I need to check my SPIP installation for this?

Yes. Your first priority is to audit your environment to see if the Crayons plugin is currently active on any of your SPIP sites. Once identified, evaluate whether those instances are internet-facing. Coordinate with your web development team to verify the plugin version and prepare for potential updates or configuration changes provided by the vendor.

References