{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/krayin-crm--2.2.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:krayin:crm:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Krayin CRM (\u003c= 2.2.6)"],"_cs_severities":["high"],"_cs_tags":["web-application","authentication-bypass","crm"],"_cs_type":"advisory","_cs_vendors":["Krayin"],"content_html":"\u003cp\u003eKrayin CRM versions through 2.2.6 contain a critical authentication bypass vulnerability identified as CVE-2026-90944. The vulnerability exists within the /admin/mail/inbound-parse endpoint, which fails to enforce authentication checks. This oversight allows remote, unauthenticated attackers to send crafted HTTP POST requests containing arbitrary RFC 2822 formatted messages. By manipulating these requests, an attacker can forge sender information, headers, subjects, and email bodies. Crucially, these messages can be injected directly into existing conversation threads within the CRM, potentially facilitating social engineering, credential harvesting, or internal misinformation campaigns by appearing as legitimate customer or internal communications. This vulnerability poses a significant risk to the integrity of business communications processed through the CRM platform.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the injection of arbitrary email content into the CRM system. This can be weaponized to conduct sophisticated social engineering attacks by inserting forged replies into active customer support or sales threads. Organizations relying on Krayin CRM to manage high-trust communications are at risk of data integrity compromise and potential financial or reputational damage if attackers successfully impersonate clients or internal staff.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict network access to the /admin/mail/inbound-parse endpoint at the web server or firewall level to trusted IP ranges only.\u003c/li\u003e\n\u003cli\u003eAudit existing CRM threads for any anomalous or unexpected email entries that may have been injected via this vulnerability.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for unauthorized POST requests directed to the /admin/mail/inbound-parse endpoint.\u003c/li\u003e\n\u003cli\u003eVerify internal Krayin CRM versioning and ensure all instances are upgraded to a version that patches CVE-2026-90944 as soon as the vendor makes such a release available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T19:35:37Z","date_published":"2026-09-14T19:35:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-krayin-crm-auth-bypass/","summary":"An authentication bypass vulnerability in Krayin CRM version 2.2.6 and earlier allows unauthenticated attackers to inject arbitrary, forged email messages into the CRM inbox via the /admin/mail/inbound-parse endpoint.","title":"Authentication Bypass in Krayin CRM Inbound Parse Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-krayin-crm-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Krayin CRM (\u003c= 2.2.6)","version":"https://jsonfeed.org/version/1.1"}