Sceawere
Vulnerability Detail
CVE-2026-100883UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Krayin Laravel-CRM Access Control Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 9h ago
- Vendor
- Krayin
- Product
- laravel-crm
- Attack Type
- Improper Access Controls
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been published and may be used. Upgrading to version 2.2.6 is sufficient to fix this issue. This patch is called a399404a388d8ad2700a01349d0d98069c8e85a4. The affected component should be upgraded.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-27T23:16:58.463Z",
"pubdate": "2026-09-27T23:16:58.463Z",
"executiveSummary": "A critical improper access control vulnerability has been identified in Krayin laravel-crm, affecting all versions up to and including 2.2.5.\nThis security flaw resides within the ACL configuration management component of the application.\nThe vulnerability allows remote, unauthenticated or unauthorized actors to circumvent established access control mechanisms, potentially gaining access to sensitive administrative functions or resources that should be protected.\nGiven that proof-of-concept exploit code has been publicly released, the risk of active exploitation is significant.\nThe vulnerability exposes the application to unauthorized data access, administrative manipulation, and potential compromise of business-critical information managed within the CRM.\nImmediate remediation is required, as the vulnerability directly undermines the integrity of the application's role-based access control (RBAC) framework.",
"technicalDetails": "The vulnerability is localized within the file 'packages/Webkul/Admin/src/Config/acl.php', which serves as the core definition file for the Access Control List (ACL) in the Krayin Laravel-CRM framework.\nThe root cause of this vulnerability lies in an improper configuration or logical flaw within the ACL definition, which fails to correctly enforce restrictive policies for specific administrative functions. By manipulating requests directed toward this component, an attacker can bypass authorization checks that are intended to verify the user's role or session privileges before executing sensitive backend operations.\nThe attack flow involves an attacker crafting malicious requests that target the vulnerable ACL configuration. Since the flaw resides in the authorization logic layer, the application fails to validate the requester's identity or permissions against the required security constraints defined for administrative routes.\nThe exploitation is remote and does not necessarily require local network access or complex environment configuration, as the CRM is web-accessible. By leveraging the publicly available exploit, an attacker can bypass the intended gatekeeping mechanisms to invoke restricted controller functions that perform CRUD operations or administrative settings changes.\nThe lack of proper validation within the 'acl.php' configuration effectively renders the RBAC system ineffective for the affected endpoints. An attacker can reach these endpoints, bypassing the security middleware that should have rejected the request due to insufficient privileges.\nPost-exploitation impact includes unauthorized exposure of CRM data, modification of user permissions, system configuration changes, and potential full administrative compromise depending on the functions exposed by the misconfigured ACL. Because the flaw is within the configuration layer, it affects the entire framework's capability to enforce granular security policies on the vulnerable components.\nThis vulnerability highlights a failure in input or session authorization mapping, where the framework fails to correctly map the user's privilege level to the permissions defined in the ACL configuration, allowing unauthorized escalation or bypass."
}