SecuFocus
BriefAnnouncements

SPIP: Crayons before 3.5.0 edits fields without an account

On 7 October 2026, CERT-FR published advisory CERTFR-2026-AVI-1279. It names SPIP before 4.4.27, Crayons before 3.5.0 and Simple logs before 2.3.0. NVD, for CVE-2026-104070, describes unauthenticated field edits in Crayons, score 9.3. The CISA catalog does not list it.

Illustration, not a SPIP screenshot. A pencil on a binder, in a dark room.

Original AI-generated illustration · SecuFocus

At a glance

Key points

If you do not run a SPIP site, this advisory does not change your evening. If you do, updating the core does not update the two plugins.

What changes

On 7 October 2026, CERT-FR published advisory CERTFR-2026-AVI-1279. It says several vulnerabilities were found in SPIP. The listed risks include remote code execution, SQL injection, privilege escalation, cross-site scripting, and loss of confidentiality and integrity. The named systems are SPIP before 4.4.27, the Crayons plugin before 3.5.0, and the Simple logs plugin before 2.3.0. The advisory gives no CVE number for the core, and none for Simple logs.

CVE-2026-104070. NVD published the record on 6 October 2026 at 17:17 UTC, and modified it the same day at 20:05 UTC. The displayed status is Awaiting Analysis. It covers the Crayons plugin for SPIP, versions before 3.5.0. An unauthenticated attacker can modify editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php. The record then describes a chain: write a malicious .html skeleton, read configuration files that hold the site secret, forge a signed ajax context, and execute that skeleton as PHP under the web-server user.

The scores read there are 9.3 in CVSS 4.0 and 9.8 in CVSS 3.1. The 4.0 vector is network access, no account, no user interaction. The CISA known-exploited catalog, version 2026.10.04, 1,734 entries, reread on 7 October 2026, does not contain CVE-2026-104070.

Three bounds, one mechanism actually read

The table copies the advisory’s version bounds. It does not say the core has the same mechanism as Crayons. For the core and for Simple logs, the advisory attaches no CVE. An NVD search on the word SPIP, limited to records published between 1 and 8 October 2026, returned only CVE-2026-104070.

Scroll the table sideways to read every column.

ComponentBound in the advisoryNVD record read
SPIPbefore 4.4.27none in this search
Crayons pluginbefore 3.5.0CVE-2026-104070
Simple logs pluginbefore 2.3.0none in this search

What we did not check

We do not run a SPIP site, and we did not replay the flaw. “Code execution” for the whole product is a risk label on the CERT-FR advisory. The NVD record we read is about Crayons. We do not cite the vendor blog: it is not on this watch’s source list. Awaiting Analysis, and absence from the CISA catalog, are not a SecuFocus test.

The choice

If you do not administer SPIP, there is nothing to install.

If you do, CERT-FR asks for a version that is not before 4.4.27, Crayons 3.5.0, and Simple logs 2.3.0. The core fix does not replace the plugin fixes. The install steps stay on the bulletins the advisory cites.

CVE-2026-104070 missing from the CISA catalog does not mean an exposed plugin can wait.

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.