CVE-2026-38529 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: April 14, 2026
Webkul Krayin CRM - Broken Access Control
Published: April 14, 2026Updated: April 14, 2026Remote Exploitable
Overview
Webkul Krayin CRM v2.2.x contains a broken access control caused by insufficient authorization checks in /Settings/UserController.php, letting authenticated attackers reset user passwords and take over accounts, exploit requires authentication.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Authenticated attackers can reset passwords and fully take over user accounts, compromising user data and system integrity.
Mitigation
Update to the latest version with proper authorization checks.
References
Related Resources
Details
- CVE ID
- CVE-2026-38529
- Severity
- High
- CVSS Score
- 8.8
- Type
- broken_access_control
- Status
- new
CWE
- CWE-269
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H