CVE-2026-41452: Krayin CRM < 2.2.1 - Installer Authentication Bypass

2026-09-16 PoC Public

Description

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware caused by bypassing the CanInstall middleware redirect check via crafted HTTP POST requests, letting unauthenticated remote attackers overwrite the primary administrator account and gain full administrative access, exploit requires crafted HTTP POST with specific header.

PoC

id: CVE-2026-41452

info:
  name: Krayin CRM < 2.2.1 - Installer Authentication Bypass
  author: str4k3r
  severity: critical
  description: |
    Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware caused by bypassing the CanInstall middleware redirect check via crafted HTTP POST requests, letting unauthenticated remote attackers overwrite the primary administrator account and gain full administrative access, exploit requires crafted HTTP POST with specific header.
  impact: |
    Unauthenticated attackers can gain full administrative access, compromising all CRM data and control.
  remediation: |
    Update to the latest version that patches this vulnerability.
  reference:
    - https://github.com/krayin/laravel-crm/releases
    - https://github.com/krayin/laravel-crm/compare/v2.2.0...v2.2.1
  classification:
    cve-id: CVE-2026-41452
    epss-score: 0.03742
    epss-percentile: 0.89559
    cwe-id: CWE-287
    cvss-score: 9.8
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  metadata:
    verified: true
    max-request: 1
    vendor: webkul
    product: krayin-laravel-crm
    fofa-query: title="Krayin" || header="krayin_crm_session"
  tags: cve,cve2026,krayin,laravel,php,installer,auth-bypass

http:
  - raw:
      - |
        GET /install HTTP/1.1
        Host: {{Hostname}}

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains_all(tolower(body), "krayin", "installation", "installer")'
        condition: and
# digest: 4b0a004830460221008af9d6206c403bd9a22f429931001335a08eb81f7c58df7ed200b4ebbdfcf686022100dc609452455afe2619b72a4b5e6889e7a7db4d21422cfa958e1da20c8695aec0:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References