CVE-2026-41452 Details
Description
Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.
A missing authentication vulnerability has been identified in Krayin CRM version 2.2.4, specifically within the installer middleware. This vulnerability allows unauthenticated remote attackers to overwrite the primary administrator account. By sending a crafted HTTP POST request to the 'admin-config-setup' endpoint, attackers can bypass the 'CanInstall' middleware's redirect check. The 'admin-config-setup' endpoint performs an unauthenticated update or insert operation targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.
Users can update to Krayin CRM version 2.2.1 or 2.2.4, both of which include the necessary fix. After updating, it is recommended to remove the Installer package from production deployments and block '/install/*' at the reverse proxy.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 3, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Krayin CRM | <= 2.2.0 (semver) >= 2.2.1, <= 2.2.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | New CVE Received | [email protected] |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
Volerion