Email Injection Vulnerability in Krayin CRM by Krayin
CVE-2026-90944
8.8HIGH
What is CVE-2026-90944?
The Krayin CRM version 2.2.6 is susceptible to an email injection issue due to the exposure of the POST /admin/mail/inbound-parse endpoint without authentication. This vulnerability allows unauthorized attackers to inject arbitrary emails into the system's inbox. By crafting malicious RFC 2822 messages with falsified sender details and headers, attackers can deliver emails with any chosen subject and body, which may include responses to ongoing conversation threads, jeopardizing data integrity and system security.
Affected Version(s)
laravel-crm 0 <= 2.2.6
