Krayin CRM Installer Middleware Authentication Bypass Leading to Admin Account Takeover
criticalOtherKrayin CRM 2.2.4 contains a critical missing authentication vulnerability that allows unauthenticated attackers to overwrite the primary administrator account by exploiting a flaw in the installer middleware bypass logic. Successful exploitation grants full administrative access to all CRM data, including customer records, credentials, and any integrated API keys or tokens.
Updated Aug 4, 2026 · CVSS 9.8