


Perceptive Security
SOC/SIEM Consultancy

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the prima…
Published:
2 August 2026 at 22:00:00
Alert date:
3 August 2026 at 18:04:46
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access, Web Technologies
Krayin CRM version 2.2.4 contains a critical missing authentication vulnerability in its installer middleware. Unauthenticated remote attackers can bypass the CanInstall middleware redirect check by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header. The vulnerability targets the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert operation against the hardcoded administrator user ID. Attackers can supply arbitrary name, email, and password values to fully overwrite the primary administrator account. Successful exploitation grants full administrative access to all CRM data without any prior authentication. The flaw is categorized as a missing authentication vulnerability and carries a high criticality rating.
Technical details
Mitigation steps:
Affected products:
Krayin CRM 2.2.4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41452
https://jivasecurity.com/writeups/krayin-installer-bypass-account-takeover-cve-2026-41452
https://www.vulncheck.com/advisories/krayin-crm-missing-authentication-via-install-api-admin-config-setup
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
