Missing Authentication Vulnerability in Krayin CRM by Krayin
CVE-2026-41452

9.3CRITICAL

Key Information:

Vendor

Krayin

Vendor
CVE Published:
3 August 2026

Badges

📈 Score: 614👾 Exploit Exists🟡 Public PoC

What is CVE-2026-41452?

CVE-2026-41452 is a vulnerability identified in Krayin CRM, specifically version 2.2.4, which is a customer relationship management platform designed for managing customer interactions, sales, and marketing efforts. This particular vulnerability arises due to a lack of proper authentication controls within the installer middleware. Attackers can exploit this flaw by issuing a specially crafted HTTP POST request, which allows them to bypass security checks and gain full administrative privileges. By targeting the admin-config-setup endpoint, attackers can overwrite the primary administrator account with arbitrary values for name, email, and password, thereby obtaining unrestricted access to all CRM data. This poses a substantial risk to organizations relying on Krayin CRM for sensitive customer and business information.

Potential impact of CVE-2026-41452

  1. Unauthorized Administrative Access: The most immediate impact is that attackers can gain full administrative rights to the CRM system without any form of authentication. This allows them to manipulate, delete, or extract sensitive data, severely compromising the integrity and confidentiality of the information stored within the CRM.

  2. Data Breaches: With administrative control, attackers can potentially leak sensitive customer and operational data, leading to data breaches that not only harm the organization’s reputation but also expose it to legal liabilities and regulatory penalties.

  3. System Compromise and Further Exploits: Once attackers secure administrative access, they can further exploit the system to introduce malicious payloads, pivot to additional systems within the network, or deploy ransomware, amplifying the overall damage and disruption to organizational operations.

Affected Version(s)

laravel-crm 0 <= 2.2.0

laravel-crm 0 <= 2.2.0

laravel-crm 2.2.4

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jiva (JivaSecurity)
.