Krayin CRM < 2.2.1 - Installer Authentication Bypass
CVE-2026-41452
Verified
Description
Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware caused by bypassing the CanInstall middleware redirect check via crafted HTTP POST requests, letting unauthenticated remote attackers overwrite the primary administrator account and gain full administrative access, exploit requires crafted HTTP POST with specific header.
Severity
Critical
CVSS Score
9.8
Exploit Probability
4%
Affected Product
krayin-laravel-crm
Published Date
September 6, 2026
Template Author
str4k3r
CVE-2026-41452.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-41452
CWE ID:
cwe-287
Remediation Steps
Update to the latest version that patches this vulnerability.