CVE-2026-38526
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.
- Affected products
- Krayin Crm
- CVSS 3.1
- 9.9 CRITICAL
- EPSS
- 3.8% (89th percentile)
- Weakness
- CWE-434
- NVD status
- Deferred
- Published
- 2026-04-14
CVE-2026-38526 at NVD
11 known exploits for CVE-2026-38526
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for CVE-2026-38526
Exploit for CVE-2026-38526
Exploit for CVE-2026-38526
Exploit for CVE-2026-38526
Krayin CRM v2.2.x - Authenticated Remote Code Execution
Exploit for CVE-2026-38526
Exploit for CVE-2026-38526
Exploit for CVE-2026-38526
Exploit for CVE-2026-38526
Exploit for CVE-2026-38526
Security-Advisories