Sceawere
Vulnerability Detail
CVE-2026-100885UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Krayin Laravel-CRM Authorization Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 9h ago
- Vendor
- Krayin
- Product
- laravel-crm
- Attack Type
- Authorization Bypass
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this issue. The patch is identified as 89f2916b6a46ff91bd1999ce38158fa0de8b9490. Upgrading the affected component is recommended.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-27T23:16:58.843Z",
"pubdate": "2026-09-27T23:16:58.843Z",
"executiveSummary": "A critical authorization bypass vulnerability exists within the Krayin laravel-crm installer middleware, affecting versions up to 2.2.4.\nThe vulnerability resides in the admin-config-setup API endpoint, specifically within the packages/Webkul/Installer/src/Http/Middleware/CanInstall.php file.\nThis security flaw allows remote, unauthenticated attackers to bypass intended access controls during the application configuration phase.\nSuccessful exploitation may lead to unauthorized system setup or reconfiguration, potentially resulting in full administrative compromise of the CRM instance.\nGiven that exploit code has been publicly disclosed, the risk of active exploitation is high.\nImmediate remediation is required to prevent unauthorized system initialization or takeover.",
"technicalDetails": "The vulnerability originates from an improper implementation of authorization logic within the 'CanInstall' middleware located at 'packages/Webkul/Installer/src/Http/Middleware/CanInstall.php'.\nIn Krayin laravel-crm, this middleware is designed to verify the installation state of the application before permitting access to sensitive setup endpoints, such as the 'admin-config-setup' API.\nThe flaw allows an attacker to circumvent these middleware checks entirely by crafting specific HTTP requests that interact with the installation process, effectively bypassing the guardrails that prevent unauthorized users from accessing or modifying the installation parameters.\nBecause this middleware fails to adequately validate the session context or the installation status before processing incoming requests, an attacker can invoke functions that are intended to be restricted to the initial configuration phase.\nThe exploitation process involves sending specially crafted network requests to the vulnerable API endpoint. Since the 'CanInstall' middleware does not correctly verify the requester's authority or the application's current state, the application proceeds to execute the requested administrative configurations.\nThis bypass effectively grants the attacker control over the initial setup process, which can be leveraged to define administrative credentials, connect to arbitrary databases, or otherwise compromise the integrity of the CRM installation.\nThe vulnerability is remotely exploitable and does not require pre-existing authentication, significantly lowering the barrier for entry for malicious actors.\nThe scope of impact is limited to the initial configuration phase; however, the post-exploitation impact includes the ability to define the site's administrative landscape, which provides persistent, high-privileged access to the application long after the installation phase has concluded.\nThis vulnerability highlights a critical failure in the request authorization pipeline where security middleware fails to maintain a 'deny-by-default' stance for restricted installation routes."
}