Junglewise Threat Intelligence

CVE-2026-100883: Krayin laravel-crm improper access control in ACL configuration

CVE-2026-100883 · Severity: medium · CVSS 6.3 · Published 2026-09-27

Technologies: Krayin Laravel-CRM. Vendors: Krayin.

Executive brief

Krayin laravel-crm is an open-source CRM application for managing customers, leads, and sales. A flaw in the access control configuration allows attackers to bypass authorization checks and access restricted functionality remotely. An attacker can escalate privileges and perform unauthorized actions within the CRM system without proper authentication.

Technical details

The vulnerability is an improper access control flaw in the packages/Webkul/Admin/src/Config/acl.php configuration file affecting function-level authorization. The issue can be exploited remotely through manipulation of the affected configuration element, allowing unauthorized access to admin functions. A patch is available in version 2.2.6 (commit a399404a388d8ad2700a01349d0d98069c8e85a4).

Affected products

  • Krayin laravel-crm up to 2.2.5

Timeline

  • 2026-09-27: disclosed

References

Related threats