CVE-2026-41452PoC

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-14); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-14: 1Mentions · 2026-08-16: 1Mentions · 2026-09-07: 1PoC Mentioned / Linked · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-16: 1Exploit Tool / Code · 2026-08-14: 1Exploit Tool / Code · 2026-08-16: 1Technical Details · 2026-08-14: 1Technical Details · 2026-08-16: 1Technical Details · 2026-09-07: 108-1408-1609-07
Signal classification3 categories
PoC
133.3%
Exploit
133.3%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-141
PoC1
2026-08-161
Exploit1
2026-09-071
Disclosure1
Full discourse3 posts
  • ThreatWire@ThreatWire_
    Exploit

    🚨 PoC RELEASED: Public exploit code is available for CVE-2026-41452, a critical authentication flaw in Krayin CRM 2.2.4. The vulnerability allows unauthenticated attackers to overwrite the primary administrator account with attacker-controlled credentials, resulting in full administrative access to CRM data. 🔗 https://github.com/boreas37/cve-2026-41452-poc #Krayin #Laravel #CVE #PoC #CyberSecurity #WebSecurity #Infosec

    Post summary

    A public PoC for CVE‑2026‑41452 has been released; the exploit allows an unauthenticated attacker to overwrite the primary administrator account in Krayin CRM 2.2.4, granting full administrative control.

    010034168.3K
    1.6K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-41452 Vendor: Laravel Product: laravel-crm (krayin) Description: Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data. Link: https://github.com/boreas37/cve-2026-41452-poc #dbugs_vuln

    Post summary

    A PoC/exploit for CVE-2026-41452 that allows overwriting the administrator account in Krayin CRM 2.2.4 has been published, with code available on GitHub, but no evidence of active exploitation or vendor remediation is reported.

    010142905
    3.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-41452 - critical 🚨 Krayin CRM < 2.2.1 - Installer Authentication Bypass > Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer mid... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-41452 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-41452, detailing a critical installer authentication bypass in Krayin CRM versions below 2.2.1, and provides a link to a detection template.

    01053592
    1.3K followersView on X

Explore more