CVE-2026-38526 is a critical authenticated file upload vulnerability leading to remote code execution
affecting Webkul Krayin CRM v2.2.x. The vulnerability exists in the TinyMCE
media upload endpoint /admin/tinymce/upload, which fails to validate uploaded
file types. An authenticated attacker can upload a malicious PHP file and execute
arbitrary commands on the server.
- CVE: CVE-2026-38526
- CVSS Score: 9.9 (Critical)
- CWE: CWE-434 - Unrestricted Upload of File with Dangerous Type
- Affected Version: Krayin Laravel CRM v2.2.x
- Vendor: Webkul
The /admin/tinymce/upload endpoint accepts multipart file uploads for the
TinyMCE rich text editor. The server performs no validation on the uploaded
file type or extension, allowing an attacker to upload a PHP webshell. The
uploaded file is stored in a web-accessible directory (/storage/tinymce/),
meaning a subsequent GET request to the file path causes the PHP interpreter
to execute the payload.
Attack flow:
- Authenticate to Krayin CRM with any valid account
- Upload a PHP webshell to
/admin/tinymce/uploadwith spoofedContent-Type: image/jpeg - Server responds with the uploaded file's URL
- Print uploaded file path
- Python 3.x
requestslibrary (pip install requests)- Valid credentials for the target Krayin CRM instance
| Flag | Description |
|---|---|
-t |
Target URL |
-u |
Login email address |
-p |
Login password |
-f |
File that will be uploaded to the target |
git clone https://github.com/NathanHimself/CVE-2026-38526-PoC
cd CVE-2026-38526-PoC
chmod +x exploit.py
python3 exploit.py -t <target URL> -u <email> -p <password> -f <file>This tool is for authorized penetration testing and educational purposes only. Do not use against systems you do not have explicit permission to test. The author assumes no responsibility and shall not be held liable for any misuse, damage, or illegal activity arising from the use of this PoC.
- https://github.com/TREXNEGRO/Security-Advisories/tree/main/CVE-2026-38526](https://socradar.io/blog/cve-2026-38526-krayin-crm-rce/)
- https://nvd.nist.gov/vuln/detail/CVE-2026-38526
This is a forked repository that I've modified to suit my needs. credit goes to the original author.