logo

CVE-2026-38526: Critical CVSS 10 Vulnerability Discovered in Krayin CRM

ID: b86c2431-2052-5f5d-87da-4dbaf8e2b89a

STIX ID: report--b86c2431-2052-5f5d-87da-4dbaf8e2b89a

Feed Name: securityonline.info

Threat Score
95/100

Date Published: 2026-04-16

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical CVE-2026-38526 RCE in Krayin CRM (v2.2.x) allows any authenticated user to upload and execute PHP payloads via the /admin/tinymce/upload endpoint due to missing MIME/extension validation and storing uploads in the web-accessible root; recommended mitigations include allowlisting MIME types/extensions, moving uploads outside the web root and serving via a controller, randomizing filenames, disabling PHP execution in upload directories, and restricting access to the endpoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.