Junglewise Threat Intelligence

CVE-2026-90944: Krayin CRM unauthenticated email injection via inbound-parse endpoint

CVE-2026-90944 · Severity: high · CVSS 8.2 · Published 2026-09-14

Technologies: Krayin CRM. Vendors: Krayin.

Executive brief

Krayin CRM is an open-source customer relationship management system for managing sales, leads, and customer interactions. The application's email inbound parser endpoint fails to require authentication, allowing attackers to inject arbitrary emails directly into the CRM inbox with forged sender information and headers. This could enable phishing attacks, fraud, or manipulation of customer communication records without any user action required.

Technical details

The vulnerability is an authentication bypass affecting the POST /admin/mail/inbound-parse endpoint in Krayin CRM through version 2.2.6. The endpoint is explicitly excluded from CSRF token validation (as seen in bootstrap/app.php), and lacks authentication middleware, making it accessible to unauthenticated attackers. An attacker can send crafted RFC 2822 formatted email messages with forged sender addresses, subjects, and body content—including replies to existing conversation threads—directly into the CRM's inbox. The vulnerability requires no authentication, CAPTCHA, or user interaction beyond network reachability to the endpoint. Updates are needed to add proper authentication and authorization checks before processing inbound email messages.

Affected products

  • Krayin CRM through 2.2.6

Timeline

  • 2026-09-14: disclosed

References