Junglewise Threat Intelligence

CVE-2026-100884: Krayin laravel-crm insecure direct object reference in attachment download

CVE-2026-100884 · Severity: medium · CVSS 4.3 · Published 2026-09-27

Technologies: Krayin Laravel-CRM. Vendors: Krayin.

Executive brief

Krayin laravel-crm is an open-source CRM platform for managing customer relationships and sales pipelines. An authenticated attacker with limited permissions can download email attachments belonging to other users by manipulating object identifiers, bypassing authorization checks. This allows unauthorized access to potentially sensitive business documents and communications.

Technical details

The vulnerability is an insecure direct object reference (IDOR) in the attachment-download endpoint caused by missing object-level authorization checks. An authenticated user can directly access the Storage::download function with an arbitrary attachment ID, with the ACL middleware unable to properly validate permissions due to an AJAX header bypass and missing authorization mapping. The vulnerability affects versions up to 2.2.5 and is fixed in version 2.2.6.

Affected products

  • Krayin laravel-crm up to 2.2.5

Timeline

  • 2026-09-27: disclosed: Vulnerability disclosed publicly
  • 2026-09-27: patched: Fixed in version 2.2.6 (commit 13d6988cda8d69ece45ee1890effc90a7f21cdc1)

References

Related threats