/Vulnerability Library

Krayin CRM < 2.2.1 - Installer Authentication Bypass

CVE-2026-41452
Verified

Description

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware caused by bypassing the CanInstall middleware redirect check via crafted HTTP POST requests, letting unauthenticated remote attackers overwrite the primary administrator account and gain full administrative access, exploit requires crafted HTTP POST with specific header.

Severity

Critical

CVSS Score

9.8

Exploit Probability

4%

Affected Product

krayin-laravel-crm

Published Date

September 6, 2026

Template Author

str4k3r

CVE-2026-41452.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-41452
CWE ID:
cwe-287

References

https://github.com/krayin/laravel-crm/releaseshttps://github.com/krayin/laravel-crm/compare/v2.2.0...v2.2.1

Remediation Steps

Update to the latest version that patches this vulnerability.