Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-38532

27
FAUCET Score

BRIEFING NOTE: CVE-2026-38532 A Broken Object-Level Authorization vulnerability exists in Webkul Krayin CRM version 2.2.x, specifically within the /Contact/Persons/PersonController.php endpoint. This flaw allows authenticated attackers to bypass authorization controls and arbitrarily access, modify, and delete contact records belonging to other users by submitting crafted GET requests. The vulnerability represents a classic authorization bypass where the application fails to properly validate whether a user should have access to requested objects. The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring low complexity and valid user credentials. While no privilege escalation is necessary, the impact is substantial: attackers gain high confidentiality and integrity compromise by reading and modifying sensitive contact data, though system availability is not directly affected. The EPSS score of 0.00032 indicates currently low predicted exploitation probability relative to other CVEs. There is no evidence of active exploitation in the wild, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog. Public exploit code availability and community attention appear minimal at this time. However, organizations running affected Krayin CRM versions should prioritize patching given the ease of exploitation by any authenticated user and the sensitivity of contact data.

Impacted Technologies

VendorProductVersion(s)CPE
2.2.0CPE matchmatch criteria
cpe:2.3:a:webkul:krayin_crm:2.2.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.35%
Probability of exploitation in next 30 days
EPSS Percentile
27.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0035 is in the 15th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

composerGHSA-2xx8-j85v-j7whhigh

Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php

Apr 14, 2026

References

github.com / krayin/laravel-crm
Product
github.com / TREXNEGRO/Security-Advisories/tree/main/CVE-2026-38532
ExploitMitigationThird Party Advisory