Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads. | |
| Title | Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parse | |
| First Time appeared |
Webkul
Webkul krayin Crm |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:webkul:krayin_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul krayin Crm |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T20:22:41.001Z
Reserved: 2026-09-14T11:34:24.687Z
Link: CVE-2026-90944
Updated: 2026-09-14T20:22:19.465Z
Status : Received
Published: 2026-09-14T18:20:28.877
Modified: 2026-09-14T21:17:43.157
Link: CVE-2026-90944
No data.
OpenCVE Enrichment
No data.
-
CWE-306
Missing Authentication for Critical Function