Broken Object-Level Authorization in Webkul Krayin CRM
CVE-2026-38532

8.1HIGH

Key Information:

Vendor

Webkul

Vendor
CVE Published:
14 April 2026

What is CVE-2026-38532?

The Webkul Krayin CRM has a vulnerability located in the /Contact/Persons/PersonController.php endpoint. This flaw allows authenticated attackers to bypass authorization controls, enabling them to read, modify, and permanently delete contacts that belong to other users through specially crafted GET requests. This lapse in object-level authorization presents a significant risk to user data integrity and confidentiality, necessitating prompt remediation.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.