CVE-2026-100884 Details
Description
A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.
An Insecure Direct Object Reference (IDOR) vulnerability has been identified in Krayin CRM versions through 2.2.5. The issue resides in the email attachment download feature, specifically within the Storage::download function of the Webkul Admin package. The vulnerability allows authenticated users to download attachments by manipulating the ID parameter, bypassing authorization checks. This flaw was confirmed through a source code review and a live proof of concept.
Users are advised to upgrade to Krayin CRM version 2.2.6, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/carlosalbertotuma/advisory/blob/main/advisory-06-IDOR-Email-Attachment%20Download.md | [email protected] | AdvisoryExploitRemedy |
| https://github.com/krayin/laravel-crm/ | [email protected] | Vendor |
| https://github.com/krayin/laravel-crm/commit/13d6988cda8d69ece45ee1890effc90a7f21cdc1 | [email protected] | Source CodeVendor |
| https://github.com/krayin/laravel-crm/issues/2624 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/krayin/laravel-crm/pull/2627 | [email protected] | Issue TrackingVendor |
| https://github.com/krayin/laravel-crm/releases/tag/v2.2.6 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-100884 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/916218 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410814 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/410814/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-99 | Improper Control of Resource Identifiers ('Resource Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Krayin CRM | <= 2.2.5 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion