Exploitation Summary
EIP tracks 12 public exploits for CVE-2026-38526. PoCs published by Diamorphine, NathanHimself, Ayham-Alazzam.
AI-analyzed exploit summary This exploit leverages an authenticated file upload vulnerability in Krayin CRM v2.2.x to upload arbitrary files (e.g., PHP shells) via the TinyMCE upload endpoint. The PoC demonstrates how to bypass authentication and upload a malicious file, enabling remote code execution.
Description
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.
Exploits (12)
This exploit leverages an authenticated file upload vulnerability in Krayin CRM v2.2.x to upload arbitrary files (e.g., PHP shells) via the TinyMCE upload endpoint. The PoC demonstrates how to bypass authentication and upload a malicious file, enabling remote code execution.
This repository contains a functional exploit for CVE-2026-38526, an authenticated RCE vulnerability in Krayin CRM v2.2.x. The exploit leverages an unrestricted file upload flaw in the TinyMCE endpoint to upload a PHP webshell and execute arbitrary commands.
This exploit targets an authenticated arbitrary file upload vulnerability in a web application's admin panel (TinyMCE upload endpoint), leading to remote code execution via a malicious PHP webshell. The PoC includes CSRF token handling, webshell upload, and reverse shell capabilities.
This exploit targets a file upload vulnerability in Krayin CRM v2.2.x, allowing authenticated attackers to upload a PHP web shell via the administrative interface's TinyMCE upload endpoint. The PoC demonstrates remote command execution by leveraging CSRF and XSRF token handling to bypass security controls.
This exploit targets an authenticated Remote Code Execution (RCE) vulnerability in Krayin CRM v2.2.x (CVE-2026-38526) via a TinyMCE file upload bypass. The PoC includes multiple PHP web shell payloads, session handling, and interactive command execution capabilities.
This exploit targets an authenticated remote code execution vulnerability in Krayin CRM v2.2.x via unrestricted file upload in TinyMCE. The PoC demonstrates uploading a PHP web shell or reverse shell by exploiting improper file type validation during upload.
This PoC exploits an unauthenticated file upload vulnerability in the `/admin/tinymce/upload` endpoint of Krayin CRM 2.2.x, allowing remote code execution via a malicious PHP file upload. The exploit chains authentication bypass with a reverse shell payload.
This PoC exploits an unauthenticated file upload vulnerability in Krayin CRM's TinyMCE upload endpoint (/admin/tinymce/upload) to achieve remote code execution (RCE) via a malicious PHP webshell. The exploit requires valid credentials for initial authentication but bypasses subsequent checks to upload arbitrary files.
This exploit targets an unrestricted file upload vulnerability in Krayin CRM's TinyMCE endpoint (/admin/tinymce/upload), bypassing MIME-type validation to upload a PHP webshell and achieve remote code execution. The PoC includes authentication, CSRF token handling, and command execution via the webshell.
This exploit leverages an authenticated arbitrary file upload vulnerability in Krayin CRM v2.2.x (CVE-2026-38526) via the TinyMCE upload endpoint. The PoC logs in with provided credentials, retrieves CSRF tokens, and uploads a malicious file (e.g., PHP shell) to achieve remote code execution.
Technical report detailing the exploitation of CVE-2026-38526, an unrestricted file upload vulnerability in Krayin CRM version 2.2.0. The writeup includes root cause analysis, step-by-step exploitation (Burp Suite interception, PHP reverse shell upload), and post-exploitation steps leading to full system compromise via a separate Gitea directory traversal flaw.
This repository contains a functional exploit for CVE-2026-38526, targeting Krayin CRM ≤ 2.2.x. The exploit leverages an unrestricted file upload vulnerability in the TinyMCE endpoint to upload a PHP webshell, enabling remote code execution via reverse shell or command injection.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H