
CVE-2026-38532 A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitra… https://www.cve.org/CVERecord?id=CVE-2026-38532
Post summary
The text discloses CVE-2026-38532 as a BOLA issue in Webkul Krayin CRM v2.2.x, noting the affected endpoint but provides no evidence of PoC, active exploitation, or remediation.

