CVE-2026-38526: Critical CVSS 10 Vulnerability Discovered in Krayin CRM
ID: b86c2431-2052-5f5d-87da-4dbaf8e2b89a
STIX ID: report--b86c2431-2052-5f5d-87da-4dbaf8e2b89a
Feed Name: securityonline.info
A critical CVE-2026-38526 RCE in Krayin CRM (v2.2.x) allows any authenticated user to upload and execute PHP payloads via the /admin/tinymce/upload endpoint due to missing MIME/extension validation and storing uploads in the web-accessible root; recommended mitigations include allowlisting MIME types/extensions, moving uploads outside the web root and serving via a controller, randomizing filenames, disabling PHP execution in upload directories, and restricting access to the endpoint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
