S4E just found a high-severity finding from cve-2026-42945 scanner (version based)
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 6, 2026

CVE-2026-41452 Scanner

CVE-2026-41452 Scanner - Missing Authorization vulnerability in Krayin CRM

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-41452
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
laravel-crmby krayin
0
Updated Sep 6, 2026View on NVD →
Detail

Krayin CRM is an open-source customer relationship management software. It is used by businesses to manage and analyze customer interactions and data throughout the customer lifecycle. The software aims to improve business relationships with customers, focusing on customer retention, and ultimately driving sales growth. Krayin CRM can be implemented in multiple ways, enabling it to be tailored to meet the specific needs of businesses of different sizes and types. Various modules and extensions can be added to enhance its functionality. The software is often praised for its flexibility and customizable capabilities.

The Missing Authorization vulnerability in Krayin CRM affects versions below 2.2.1. It allows unauthenticated attackers to bypass the middleware responsible for redirect checks during the installation process. By crafting specific HTTP POST requests, attackers can bypass the CanInstall middleware redirect. This security flaw opens the CRM to full administrative access by attackers, allowing them to overwrite the primary administrator account. This vulnerability is critical, given the wide array of sensitive data handled within CRM systems.

The technical details of the vulnerability include the ability for crafted HTTP POST requests to bypass security checks during the installation phase. Attackers can manipulate header information and exploit the lack of proper authentication checks. The primary vulnerable endpoint is the installer route, which should have robust authentication to prevent unauthorized access. Attackers can exploit the missing authentication check to gain control over administrative functions. This weakness is particularly concerning as it compromises the security integrity of the CRM system.

If exploited by malicious actors, the Missing Authorization vulnerability can lead to significant security breaches. Attackers gaining administrative access can result in data theft, unauthorized data modification, and disruption of services. The CRM system, which typically contains valuable customer data and business information, becomes susceptible to breaches affecting data confidentiality, integrity, and availability. Businesses relying on the CRM are at risk of losing customer trust and facing potential legal and financial repercussions.

REFERENCES

Solution Advice
Remediation:
  • Update Krayin CRM to version 2.2.4 or later to ensure the vulnerability is patched.
  • Regularly review and audit CRM installation security configurations.
  • Implement network intrusion detection systems to monitor unauthorized access attempts.
  • Ensure proper security protocols and middleware checks are in place during software installations.
  • Conduct regular security training and awareness programs for staff managing CRM systems.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.