Improper Resource Control in Krayin Laravel CRM by Webkul
CVE-2026-100884
Key Information:
- Vendor
Krayin
- Status
- Vendor
- CVE Published:
- 27 September 2026
Badges
What is CVE-2026-100884?
A vulnerability in the Krayin Laravel CRM, specifically in versions up to 2.2.5, has been identified. The flaw lies in the Storage::download function within the acl.php file of the attachment-download endpoint, where inadequate control over resource identifiers allows for potential exploitation. Attackers can manipulate the argument ID and initiate remote unauthorized actions, posing a significant security risk. It is crucial for users to promptly upgrade to version 2.2.6 or later to mitigate this vulnerability.
Affected Version(s)
laravel-crm 2.2.0
laravel-crm 2.2.1
laravel-crm 2.2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
