SPIP CMS critical fixes (6 Oct): SPIP 4.4.27 patches pre-authentication RCE and more, and the Crayons plugin (CVE-2026-104070, CVSS 9.8) and Simple logs plugin need urgent updates to 3.5.0 and 2.3.0
The SPIP maintenance team released two critical security updates on 6 October 2026 for SPIP, the French open-source content management system widely used by public bodies and associations in France. SPIP 4.4.27 (4.4.26 was skipped) fixes many flaws, which the team describes as pre-authentication remote code execution, privilege escalation, cross-site scripting, SQLite injection, anonymous HTML upload and reconstruction of the site secret. SPIP warns that its security screen, the protective filter many sites rely on between releases, does not block these. Separately, the Crayons plugin, which lets editors change content directly on the page, was updated to 3.5.0 and the Simple logs (Simplog) plugin to 2.3.0. One Crayons flaw, CVE-2026-104070 (CVSS 3.1 9.8, CVSS 4.0 9.3), lets an unauthenticated attacker skip the authorization check in crayons_store.php by leaving out the anti-forgery parameter, then chain it to write a malicious template file, read the configuration that holds the site secret, and run PHP code as the web server user. The Simplog flaw allows reading and deleting any file in the installation, which can be used to reinstall the site and create a webmaster account. No exploitation has been reported. Primary: SPIP blog; CVE record and VulnCheck advisory.
- Product
- SPIP CMS core; Crayons plugin; Simple logs (Simplog) plugin
- Versions
- SPIP before 4.4.27; Crayons before 3.5.0; Simple logs before 2.3.0
- CVSS
- Critical (CVE-2026-104070, CVSS 3.1; 9.3 CVSS 4.0, per CVE record)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade SPIP to 4.4.27 and, where installed, Crayons to 3.5.0 and Simple logs to 2.3.0, all at once. Do not rely on the SPIP security screen for these flaws. After updating, check for unexpected template (.html) files and new webmaster accounts, and change the site secret and administrator passwords if a site was exposed.
Primary: SPIP Blog — Mises à jour de sécurité critique : plugins Crayons et Simplog (6 Oct 2026, French) · Vendor: SPIP Blog — Mise à jour critique de sécurité : sortie de SPIP 4.4.27 (6 Oct 2026, French) · CVE: CVE-2026-104070 · VulnCheck — SPIP Crayons plugin authorization bypass RCE (CVE-2026-104070)
