CVE-2026-36340 Details
Description
An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function
A remote code execution vulnerability has been identified in Krayin CRM version 2.1.5. This issue allows authenticated users to execute arbitrary code by uploading malicious PHP files through the email composition feature. The uploaded files are stored in a publicly accessible directory without proper validation, allowing the executed payloads to be accessed via their URLs.
Users are advised to update to Krayin CRM version 2.1.6, which addresses this vulnerability. Additionally, implement measures such as restricting allowed file extensions, validating MIME types, storing uploads outside publicly accessible directories, blocking execution of uploaded files via web server rules, and monitoring upload directories for suspicious files.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 30, 2026CISA-ADP
Assessed Apr 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cybercrewinc/CVE-2026-36340 | CISA-ADP | ExploitRemedy |
| https://drive.google.com/file/d/1yBdvbrXGf9fsFckmK9zTe2v8_vDtdicH/view | [email protected] | ExploitPartial Content |
| https://github.com/cybercrewinc/CVE-2026-36340 | [email protected] | ExploitRemedy |
| https://github.com/krayin/laravel-crm/releases/tag/v2.1.6 | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Krayin CRM | 2.1.5 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | New CVE Received | [email protected] |
Volerion