BRIEFING NOTE: CVE-2026-38532 A Broken Object-Level Authorization vulnerability exists in Webkul Krayin CRM version 2.2.x, specifically within the /Contact/Persons/PersonController.php endpoint. This flaw allows authenticated attackers to bypass authorization controls and arbitrarily access, modify, and delete contact records belonging to other users by submitting crafted GET requests. The vulnerability represents a classic authorization bypass where the application fails to properly validate whether a user should have access to requested objects. The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring low complexity and valid user credentials. While no privilege escalation is necessary, the impact is substantial: attackers gain high confidentiality and integrity compromise by reading and modifying sensitive contact data, though system availability is not directly affected. The EPSS score of 0.00032 indicates currently low predicted exploitation probability relative to other CVEs. There is no evidence of active exploitation in the wild, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog. Public exploit code availability and community attention appear minimal at this time. However, organizations running affected Krayin CRM versions should prioritize patching given the ease of exploitation by any authenticated user and the sensitivity of contact data.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.0CPE matchmatch criteria | cpe:2.3:a:webkul:krayin_crm:2.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.