CVE-2026-38530: High severity Webkul krayin crm vulnerability
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-38530?
CVE-2026-38530 is classified as a critical vulnerability due to its potential for unauthorized access and data manipulation.
How do I fix CVE-2026-38530?
To fix CVE-2026-38530, it is recommended to upgrade Webkul Krayin CRM to version 2.3.0 or later where the issue is addressed.
What type of attack can exploit CVE-2026-38530?
CVE-2026-38530 can be exploited by authenticated attackers to read, modify, or delete leads owned by other users.
What software versions are affected by CVE-2026-38530?
CVE-2026-38530 affects Webkul Krayin CRM versions between 2.2.0 and below 2.3.0.
Is authentication required to exploit CVE-2026-38530?
Yes, CVE-2026-38530 requires authentication for exploitation, allowing attackers with valid accounts to perform unauthorized actions.