Junglewise Threat Intelligence

CVE-2026-100885: Krayin laravel-crm authentication bypass in installer

CVE-2026-100885 · Severity: high · CVSS 7.3 · Published 2026-09-27

Technologies: Krayin Laravel-CRM. Vendors: Krayin.

Executive brief

Krayin laravel-crm is an open-source customer relationship management system built with Laravel. After installation, the installer component remains accessible and can be exploited by an unauthenticated attacker to take over the super administrator account by simply sending an HTTP header. An attacker can change the admin username, email, and password, gaining complete administrative control of the CRM system.

Technical details

An authentication bypass in the installer middleware (CanInstall.php) allows unauthenticated access to the admin-config-setup API endpoint when the X-Requested-With: XMLHttpRequest header is present. The vulnerable endpoint allows modification of existing administrator credentials without authentication. The fix is available in version 2.2.5 (patch 89f2916b6a46ff91bd1999ce38158fa0de8b9490).

Affected products

  • Krayin laravel-crm up to 2.2.4

Timeline

  • 2026-09-27: disclosed
  • 2026-09-27: patched: Version 2.2.5 released with fix

References

Related threats