{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3akrayinlaravel-crm/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:krayin:laravel-crm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-100885"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["laravel-crm (\u003c= 2.2.4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","authentication-bypass"],"_cs_type":"threat","_cs_vendors":["Krayin"],"content_html":"\u003cp\u003eKrayin laravel-crm versions up to and including 2.2.4 are vulnerable to an authorization bypass flaw located within the CanInstall middleware (packages/Webkul/Installer/src/Http/Middleware/CanInstall.php). This vulnerability resides in the admin-config-setup API endpoint and enables remote, unauthenticated actors to bypass authorization checks. If successfully exploited, an attacker could interact with sensitive installation or configuration functions, potentially leading to a full compromise of the CRM application's setup state. A proof-of-concept exploit is publicly available, increasing the risk of active exploitation. Defenders should prioritize patching, as this vulnerability provides a direct pathway for unauthorized administrative access to the platform.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows remote attackers to bypass security authorization, which may result in unauthorized modification of CRM configurations or the ability to perform administrative installation tasks. This could lead to data exposure, account takeover, or complete loss of control over the affected Krayin laravel-crm instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Krayin laravel-crm to version 2.2.5 or later to resolve the vulnerability addressed by patch 89f2916b6a46ff91bd1999ce38158fa0de8b9490.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST or GET requests targeting the /admin/config/setup or related installation endpoints, particularly from unexpected source IP addresses.\u003c/li\u003e\n\u003cli\u003eRestrict access to administrative and installation endpoints at the network perimeter (firewall/WAF) to only authorized management subnets until patching is completed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T01:11:18Z","date_published":"2026-09-28T01:11:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-krayin-auth-bypass/","summary":"An authorization bypass vulnerability in the Krayin laravel-crm CanInstall middleware allows remote attackers to manipulate the admin-config-setup endpoint to circumvent security controls.","title":"Authorization Bypass in Krayin laravel-crm","url":"https://feed.craftedsignal.io/briefs/2026-09-krayin-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:krayin:laravel-Crm:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}