Broken Object-Level Authorization in Webkul Krayin CRM
CVE-2026-38530
8.1HIGH
What is CVE-2026-38530?
A vulnerability in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated users to exploit broken object-level authorization, enabling them to read, modify, or permanently delete leads owned by other users. This security flaw arises from improper checks related to the ownership of leads, creating significant risks for data integrity and privacy. Attackers can craft specific GET requests to manipulate lead data, which highlights the pressing need for stronger authorization controls within the application.
