PT-2026-57273 · Unknown · Krayin Crm

·

CVE-2026-61460

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Krayin CRM versions prior to 2.2.4
Description An insecure direct object reference issue exists where authenticated users can edit, update, or delete records belonging to other users. This occurs due to missing record-level ownership validation within the edit(), update(), and destroy() methods of the following controllers: LeadController, PersonController, OrganizationController, QuoteController, and ActivityController. An attacker can exploit this to modify CRM records and reassign ownership.
Recommendations Update Krayin CRM to version 2.2.4 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61460

Affected Products

Krayin Crm