CVE-2026-61460
Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or delete records owned by other users. Attackers can modify CRM records and reassign ownership by exploiting missing record-level ownership validation in edit, update, and destroy methods.
- Affected products
- Krayin Crm
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.3% (20th percentile)
- Weakness
- CWE-639
- NVD status
- Deferred
- Published
- 2026-07-10
CVE-2026-61460 at NVD
No indexed exploits for CVE-2026-61460 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-61460 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.