CVE-2026-90944
Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parse
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads.
| CWE | CWE-306 |
| Vendor | krayin |
| Product | laravel-crm |
| Published | Sep 14, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for krayin laravel-crm
Be the first to know when new high vulnerabilities affecting krayin laravel-crm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
Low
Affected Versions
krayin / laravel-crm
0 โค 2.2.6
References
github.com: https://github.com/krayin/laravel-crm/issues/2560 github.com: https://github.com/krayin/laravel-crm github.com: https://github.com/krayin/laravel-crm/blob/v2.2.6/packages/Webkul/Admin/src/Routes/Admin/mail-routes.php github.com: https://github.com/krayin/laravel-crm/blob/v2.2.6/bootstrap/app.php vulncheck.com: https://www.vulncheck.com/advisories/krayin-crm-through-2.2.6-unauthenticated-email-injection-via-inbound-parse
Credits
๐ George Chen