CVE-2026-100885 Details
Description
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this issue. The patch is identified as 89f2916b6a46ff91bd1999ce38158fa0de8b9490. Upgrading the affected component is recommended.
An authorization bypass vulnerability has been identified in Krayin Laravel-CRM versions through 2.2.4. The issue resides in the installer middleware, which fails to properly restrict access to certain API endpoints after the application has been installed. This vulnerability allows remote, unauthenticated attackers to invoke the 'admin-config-setup' endpoint via AJAX, bypassing installation safeguards. Exploiting this flaw enables attackers to overwrite super administrator credentials, including username, email, and password, leading to full administrative access.
Upgrade to Krayin Laravel-CRM version 2.2.5, which addresses this vulnerability by removing unauthorized access to the installer API after the application is installed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/carlosalbertotuma/advisory/blob/main/advisory-07-Unauthenticated-InstallerBypass.md | [email protected] | AdvisoryExploitRemedy |
| https://github.com/krayin/laravel-crm/ | [email protected] | ProductVendor |
| https://github.com/krayin/laravel-crm/commit/89f2916b6a46ff91bd1999ce38158fa0de8b9490 | [email protected] | Source CodeVendor |
| https://github.com/krayin/laravel-crm/pull/2614 | [email protected] | Issue TrackingVendor |
| https://github.com/krayin/laravel-crm/releases/tag/v2.2.5 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-100885 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/916597 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410815 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/410815/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Krayin | 2.2.4 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion