CVE-2026-100884
Krayin laravel-crm attachment-download Endpoint acl.php resource injection
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.
| CWE | CWE-99 |
| Vendor | krayin |
| Product | laravel-crm |
| Published | Sep 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for krayin laravel-crm
Be the first to know when new medium vulnerabilities affecting krayin laravel-crm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Krayin / laravel-crm
2.2.0 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5
References
vuldb.com: https://vuldb.com/vuln/410814 vuldb.com: https://vuldb.com/vuln/410814/cti vuldb.com: https://vuldb.com/cve/CVE-2026-100884 vuldb.com: https://vuldb.com/submit/916218 github.com: https://github.com/krayin/laravel-crm/issues/2624 github.com: https://github.com/krayin/laravel-crm/pull/2627 github.com: https://github.com/carlosalbertotuma/advisory/blob/main/advisory-06-IDOR-Email-Attachment%20Download.md github.com: https://github.com/krayin/laravel-crm/commit/13d6988cda8d69ece45ee1890effc90a7f21cdc1 github.com: https://github.com/krayin/laravel-crm/releases/tag/v2.2.6 github.com: https://github.com/krayin/laravel-crm/
Credits
๐ bl4dsc4n (VulDB User)