SPIP: Crayons before 3.5.0 edits fields without an account
On 7 October 2026, CERT-FR published advisory CERTFR-2026-AVI-1279. It names SPIP before 4.4.27, Crayons before 3.5.0 and Simple logs before 2.3.0. NVD, for CVE-2026-104070, describes unauthenticated field edits in Crayons, score 9.3. The CISA catalog does not list it.

Original AI-generated illustration · SecuFocus
At a glance
Key points
If you do not run a SPIP site, this advisory does not change your evening. If you do, updating the core does not update the two plugins.
What changes
On 7 October 2026, CERT-FR published advisory CERTFR-2026-AVI-1279. It says several vulnerabilities were found in SPIP. The listed risks include remote code execution, SQL injection, privilege escalation, cross-site scripting, and loss of confidentiality and integrity. The named systems are SPIP before 4.4.27, the Crayons plugin before 3.5.0, and the Simple logs plugin before 2.3.0. The advisory gives no CVE number for the core, and none for Simple logs.
CVE-2026-104070. NVD published the record on 6 October 2026 at 17:17 UTC, and modified it the same day at 20:05 UTC. The displayed status is Awaiting Analysis. It covers the Crayons plugin for SPIP, versions before 3.5.0. An unauthenticated attacker can modify editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php. The record then describes a chain: write a malicious .html skeleton, read configuration files that hold the site secret, forge a signed ajax context, and execute that skeleton as PHP under the web-server user.
The scores read there are 9.3 in CVSS 4.0 and 9.8 in CVSS 3.1. The 4.0 vector is network access, no account, no user interaction. The CISA known-exploited catalog, version 2026.10.04, 1,734 entries, reread on 7 October 2026, does not contain CVE-2026-104070.
Three bounds, one mechanism actually read
The table copies the advisory’s version bounds. It does not say the core has the same mechanism as Crayons. For the core and for Simple logs, the advisory attaches no CVE. An NVD search on the word SPIP, limited to records published between 1 and 8 October 2026, returned only CVE-2026-104070.
Scroll the table sideways to read every column.
| Component | Bound in the advisory | NVD record read |
|---|---|---|
| SPIP | before 4.4.27 | none in this search |
| Crayons plugin | before 3.5.0 | CVE-2026-104070 |
| Simple logs plugin | before 2.3.0 | none in this search |
What we did not check
We do not run a SPIP site, and we did not replay the flaw. “Code execution” for the whole product is a risk label on the CERT-FR advisory. The NVD record we read is about Crayons. We do not cite the vendor blog: it is not on this watch’s source list. Awaiting Analysis, and absence from the CISA catalog, are not a SecuFocus test.
The choice
If you do not administer SPIP, there is nothing to install.
If you do, CERT-FR asks for a version that is not before 4.4.27, Crayons 3.5.0, and Simple logs 2.3.0. The core fix does not replace the plugin fixes. The install steps stay on the bulletins the advisory cites.
CVE-2026-104070 missing from the CISA catalog does not mean an exposed plugin can wait.
Check and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.