Description
Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Email Injection
Action: Apply Patch
AI Analysis

Impact

Krayin CRM up to version 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing an attacker to submit a crafted RFC 2822 message and have it stored as an inbound email in the system. The weakness is an authentication bypass (CWE‑306), and the injection permits the sender address, subject, body and header fields to be chosen by the attacker, including reply-to values that could associate the message with an existing conversation thread.

Affected Systems

The vulnerability affects Krayin CRM (Laravel‑CRM) version 2.2.6 and earlier releases. No other products or versions are listed by the CNA.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP POST request to /admin/mail/inbound-parse, which can be performed over the public Internet if the CRM instance is reachable. Successful exploitation would allow an attacker to inject arbitrary emails into the system, compromising the integrity of inbound mail processing.

Generated by OpenCVE AI on September 15, 2026 at 12:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch that ensures authentication is required on the /admin/mail/inbound-parse endpoint
  • Configure the web server or an application firewall to block or rate‑limit unauthenticated requests to /admin/mail/inbound-parse
  • If no patch is available, restrict access to the endpoint using IP whitelisting or a VPN

Generated by OpenCVE AI on September 15, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Krayin
Krayin laravel-crm
Vendors & Products Krayin
Krayin laravel-crm

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads.
Title Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parse
First Time appeared Webkul
Webkul krayin Crm
Weaknesses CWE-306
CPEs cpe:2.3:a:webkul:krayin_crm:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul krayin Crm
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Krayin Laravel-crm
Webkul Krayin Crm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:04.713Z

Reserved: 2026-09-14T11:34:24.687Z

Link: CVE-2026-90944

cve-icon Vulnrichment

Updated: 2026-09-14T20:22:19.465Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:20:28.877

Modified: 2026-09-24T20:43:32.537

Link: CVE-2026-90944

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:00:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function