
CVE-2026-38530 A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrar… https://www.cve.org/CVERecord?id=CVE-2026-38530
Post summary
The text announces CVE-2026-38530 as a BOLA vulnerability in Webkul Krayin CRM v2.2.x, detailing the affected endpoint and potential impact, but provides no PoC, exploit code, active exploitation evidence, or patch information.

