
CVE-2026-36340 An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function https://www.cve.org/CVERecord?id=CVE-2026-36340
Post summary
CVE-2026-36340 allows remote execution in Krayin CRM v2.1.5 via the compose email function; a patch (v2.1.6) is already available.


