logo

CVE-2026-38526 in Krayin CRM Enables RCE

ID: 7d780c0c-1a56-5106-ae1a-a2810ece23e8

STIX ID: report--7d780c0c-1a56-5106-ae1a-a2810ece23e8

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-04-21

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

CVE-2026-38526 is a critical (CVSS 9.9) authenticated arbitrary file upload vulnerability in Webkul Krayin CRM (v2.2.x) that allows low-privilege authenticated users to upload PHP payloads through the TinyMCE admin media upload endpoint and achieve remote code execution; a public PoC and exploit-sharing have been observed, so internet-exposed or widely accessible admin panels should be treated as high priority. Mitigations include disabling PHP execution in upload directories, storing uploads outside the web root, restricting the upload endpoint to trusted roles and networks, and monitoring for suspicious upload and GET activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.