Missing Authentication Vulnerability in Krayin CRM by Krayin
CVE-2026-41452
Key Information:
- Vendor
Krayin
- Status
- Vendor
- CVE Published:
- 3 August 2026
Badges
What is CVE-2026-41452?
Krayin CRM version 2.2.4 is susceptible to a vulnerability in its installer middleware that enables unauthorized remote attackers to compromise the primary administrator account. By crafting a specific HTTP POST request with an X-Requested-With: XMLHttpRequest header, attackers can circumvent the CanInstall middleware's checks. This flaw permits unauthorized individuals to submit arbitrary values for account name, email, and password through the admin-config-setup endpoint. The intermediary updateOrInsert method that targets a hardcoded administrator user ID effectively grants complete administrative control over the CRM data.
Affected Version(s)
laravel-crm 0 <= 2.2.0
laravel-crm 0 <= 2.2.0
laravel-crm 2.2.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
