CVE-2026-61460

HIGH

Krayin CRM Insecure Direct Object Reference via Controllers

Title source: cna
STIX 2.1

Description

Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or delete records owned by other users. Attackers can modify CRM records and reassign ownership by exploiting missing record-level ownership validation in edit, update, and destroy methods.

References (3)

Core 3
Core References
Exploit technical-description exploit
Researcher Disclosure
https://github.com/krayin/laravel-crm/issues/2559
Issue Tracking issue-tracking
Pull Request
https://github.com/krayin/laravel-crm/pull/2567

Scores

CVSS v3 8.8
EPSS 0.0028
EPSS Percentile 20.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-639
Status published
Products (1)
krayin/laravel-crm < 2.2.3
Published Jul 10, 2026
Tracked Since Jul 11, 2026