CVE-2026-90944
Received Received - Intake

Unauthenticated Email Injection in Krayin CRM

Vulnerability report for CVE-2026-90944, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
krayin crm 2.2.6
krayin laravel-crm 2.2.6
krayin laravel-crm to 2.2.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Krayin CRM through version 2.2.6 has an unauthenticated endpoint POST /admin/mail/inbound-parse. This allows attackers to send crafted emails to the CRM inbox without any authentication. The emails can have arbitrary sender information, headers, subjects, and body content, including replies to existing conversations.

Detection Guidance

Check for unauthorized access to the POST /admin/mail/inbound-parse endpoint by monitoring web server logs for requests to this path without authentication. Look for unusual email injection attempts or forged sender information in inbox entries.

Impact Analysis

An attacker could inject malicious or deceptive emails into your CRM system. This could lead to phishing attacks, misinformation spread to users, or unauthorized access to sensitive information. The impact includes potential data breaches, reputational damage, and operational disruptions.

Compliance Impact

This vulnerability could lead to unauthorized data access or exposure, violating GDPR's data protection principles or HIPAA's security requirements. It may result in non-compliance due to potential data breaches, lack of authentication controls, and inability to ensure data integrity and confidentiality.

Mitigation Strategies

Immediately restrict access to the POST /admin/mail/inbound-parse endpoint by implementing authentication or IP whitelisting. Update Krayin CRM to the latest version if a patch is available. Monitor inbox entries for suspicious emails and review server logs for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90944. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart