id: CVE-2026-41452 info: name: Krayin CRM < 2.2.1 - Installer Authentication Bypass author: str4k3r severity: critical description: | Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware caused by bypassing the CanInstall middleware redirect check via crafted HTTP POST requests, letting unauthenticated remote attackers overwrite the primary administrator account and gain full administrative access, exploit requires crafted HTTP POST with specific header. impact: | Unauthenticated attackers can gain full administrative access, compromising all CRM data and control. remediation: | Update to the latest version that patches this vulnerability. reference: - https://github.com/krayin/laravel-crm/releases - https://github.com/krayin/laravel-crm/compare/v2.2.0...v2.2.1 classification: cve-id: CVE-2026-41452 epss-score: 0.02454 epss-percentile: 0.83355 cwe-id: CWE-287 cvss-score: 9.8 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H metadata: verified: true max-request: 1 vendor: webkul product: krayin-laravel-crm fofa-query: title="Krayin" || header="krayin_crm_session" tags: cve,cve2026,krayin,laravel,php,installer,auth-bypass http: - raw: - | GET /install HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_all(tolower(body), "krayin", "installation", "installer")' condition: and # digest: 4b0a00483046022100c876a60595631a73df72990ed2ba47b93ba91ce376320e7e4640c3e23894e0db022100e6961d132ab7edc7118321a1fa41e6e7c31a6146c6247ce36875217d83103892:922c64590222798bb761d5b6d8e72950