Broken Object-Level Authorization in Webkul Krayin CRM
CVE-2026-38530

8.1HIGH

Key Information:

Vendor

Webkul

Vendor
CVE Published:
14 April 2026

What is CVE-2026-38530?

A vulnerability in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated users to exploit broken object-level authorization, enabling them to read, modify, or permanently delete leads owned by other users. This security flaw arises from improper checks related to the ownership of leads, creating significant risks for data integrity and privacy. Attackers can craft specific GET requests to manipulate lead data, which highlights the pressing need for stronger authorization controls within the application.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.