Webkul Krayin CRM v2.2.x was assigned two high-severity vulnerabilities, CVE-2026-38529 and CVE-2026-38530, both caused by Broken Object-Level Authorization (BOLA) weaknesses in application endpoints. The first flaw affects /Settings/UserController.php and allows an authenticated attacker to reset other users’ passwords with a crafted HTTP request, creating a path to full account takeover and broad impact on confidentiality, integrity, and availability.
The second flaw affects /Controllers/Lead/LeadController.php and lets an authenticated attacker use a crafted GET request to access lead records belonging to other users. An attacker can arbitrarily read, modify, and permanently delete those leads, exposing sensitive CRM data and enabling unauthorized manipulation of business records. Public references point to the Krayin CRM GitHub repository and security advisories documenting the issues.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On April 14, 2026, CVE-2026-38532 was received by cve@mitre.org for Webkul Krayin CRM v2.2.x. The authenticated BOLA flaw in the PersonController endpoint allows attackers to access, modify, and permanently delete other users’ contact records via crafted GET requests.
On April 14, 2026, CVE-2026-38529 and CVE-2026-38530 were received by cve@mitre.org for Webkul Krayin CRM v2.2.x. The reported issues describe authenticated Broken Object-Level Authorization flaws enabling password resets for other users and unauthorized access to other users' leads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.