{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/krayin-crm-2.2.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-41452"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Krayin CRM (2.2.4)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","crm","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["Krayin"],"content_html":"\u003cp\u003eKrayin CRM version 2.2.4 is affected by a critical missing authentication vulnerability (CVE-2026-41452) located within the installer middleware. An unauthenticated remote attacker can bypass the CanInstall middleware redirect by including a specific HTTP header, 'X-Requested-With: XMLHttpRequest', in a POST request directed at the application's configuration endpoint. This flaw permits the attacker to interact with the 'admin-config-setup' endpoint, which contains an 'updateOrInsert' function targeting the hardcoded primary administrator user ID. By submitting arbitrary name, email, and password values, an attacker can overwrite existing administrator credentials, resulting in full administrative compromise of the CRM instance. This vulnerability is of high concern due to the ease of exploitation and the potential for full data access and administrative control over the target CRM environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain full administrative access to Krayin CRM instances. This grants the attacker unrestricted access to all stored CRM data, including customer records, sales information, and communications, as well as the ability to modify system settings or further persist within the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict access to the CRM installer endpoints using network-level controls until the vendor releases a security update for Krayin CRM 2.2.4.\u003c/li\u003e\n\u003cli\u003eAudit access logs for unauthorized HTTP POST requests directed to the 'admin-config-setup' URI path, specifically looking for requests containing the 'X-Requested-With: XMLHttpRequest' header originating from unauthorized IP addresses.\u003c/li\u003e\n\u003cli\u003eReview administrative user accounts for anomalous changes or unknown credentials that may indicate post-exploitation account takeover.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T18:05:46Z","date_published":"2026-08-03T18:05:46Z","id":"https://feed.craftedsignal.io/briefs/2026-08-krayin-auth-bypass/","summary":"Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware, allowing unauthenticated remote attackers to overwrite the administrator account via crafted HTTP POST requests.","title":"Krayin CRM Installer Authentication Bypass Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-krayin-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Krayin CRM (2.2.4)","version":"https://jsonfeed.org/version/1.1"}