๐Ÿ” CVE Alert

CVE-2026-90944

HIGH 8.2

Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parse

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads.

CWE CWE-306
Vendor krayin
Product laravel-crm
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for krayin laravel-crm

Be the first to know when new high vulnerabilities affecting krayin laravel-crm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
Low

Affected Versions

krayin / laravel-crm
0 โ‰ค 2.2.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/krayin/laravel-crm/issues/2560 github.com: https://github.com/krayin/laravel-crm github.com: https://github.com/krayin/laravel-crm/blob/v2.2.6/packages/Webkul/Admin/src/Routes/Admin/mail-routes.php github.com: https://github.com/krayin/laravel-crm/blob/v2.2.6/bootstrap/app.php vulncheck.com: https://www.vulncheck.com/advisories/krayin-crm-through-2.2.6-unauthenticated-email-injection-via-inbound-parse

Credits

๐Ÿ” George Chen