CVE-2026-38526
Author
Harry178945
Published
2026-09-28
Stars
0
Forks
0
Repository
Description
CVE-2026-38526 - Authenticated RCE exploit for Krayin CRM = 2.2.x. Upload arbitrary PHP via /admin/tinymce/upload and gain remote code execution. Python PoC for security researchers, CTF players and bug bounty hunters. Tested on HTB Nexus.
CVE-CVE-2026-38526 Details
Severity
CRITICAL
CVSS Score
9.9
CWE
CWE-434
Description
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file....
Related PoCs for CVE-2026-38526
htb-labs-nexus...
0
DiegoRivas1
Gitea-template-sync-Path-Traversal-Privi...
0
Shirouuu