CVE-2026-38526
published 2026-04-14CVE-2026-38526: An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary…
PriorityP273critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EXPLOIT
EPSS
3.82%
89.4th percentile
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.
Detection & IOCsextracted from sources · hover to see the quote
- →Detect POST requests to /admin/tinymce/upload where the uploaded file has a PHP extension but is sent with a spoofed MIME type (e.g., image/jpeg). This is the core bypass technique used in the exploit. ↗
- →Monitor for the presence of the X-XSRF-TOKEN header in POST requests to /admin/tinymce/upload, combined with a multipart file upload containing a .php file — this matches the exploit's authentication and upload flow. ↗
- ·Exploitation requires prior authentication (valid CRM credentials). The vulnerability is not unauthenticated; defenders should treat any authenticated user as a potential threat vector for this endpoint. ↗
- ·The exploit was tested on Debian. Detection and patching efforts should prioritize Linux-based deployments of Krayin CRM v2.2.x. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Krayin CRM 2.2.x /admin/tinymce/upload unrestricted upload (EDB-52629)
vuldb·2026-07-14·CVSS 9.9
CVE-2026-38526 [CRITICAL] Krayin CRM 2.2.x /admin/tinymce/upload unrestricted upload (EDB-52629)
A vulnerability described as critical has been identified in Krayin CRM 2.2.x. Affected is an unknown function of the file /admin/tinymce/upload. Executing a manipulation can lead to unrestricted upload.
The identification of this vulnerability is CVE-2026-38526. The attack may be launched remotely. Furthermore, there is an exploit available.
GHSA
GHSA-j8gj-mw5g-642g: An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2
ghsa_unreviewed·2026-04-14
CVE-2026-38526 [CRITICAL] CWE-434 GHSA-j8gj-mw5g-642g: An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.
No detection rules found.
No writeups or analysis indexed.
2026-04-14
Published