CVE-2026-97895: krayin laravel-crm User Management UserController.php privileges management
A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing a manipulation of the argument roleid can lead to improper privilege management. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.2.6 is able to mitigate this issue. This patch is called 5469d70336fbb25e8e513683e82b32982ce8aa82. Upgrading the affected component is advised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
krayin/laravel-crmto a version that resolves this vulnerability.Fixed in 2.2.6Patch 5469d70336fbb25e8e513683e82b32982ce8aa82
Event History
Frequently Asked Questions
Which deployments are affected?
Krayin Laravel CRM versions up to and including 2.2.5 are affected. Version 2.2.6 mitigates the issue.
What access does an attacker need to exploit this issue?
The attack is remote and requires low privileges. Exploitation involves manipulating the role_id argument in the User Management UserController component; no user interaction is required.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.
What should teams do if they are affected?
Upgrade the affected component to version 2.2.6. The mitigation patch is identified as 5469d70336fbb25e8e513683e82b32982ce8aa82.