Krayin CRM through version 2.2.3 contains a high-severity insecure direct object reference vulnerability, tracked as CVE-2026-61460, that allows authenticated users to access and manipulate records owned by other users. The flaw affects LeadController, PersonController, OrganizationController, QuoteController, and ActivityController, where record-level ownership checks are missing from edit, update, and delete-related methods even though route-level access controls are present.
The issue allows low-privileged attackers to remotely edit, update, delete, and reassign ownership of CRM data, including by changing fields such as user_id. Public reporting said the weakness stems from inconsistent authorization enforcement in controller logic, with some view paths validating ownership while modification paths do not. The vulnerability is classified as CWE-639 and has been rated High severity, with remediation focused on enforcing ownership validation in affected controller methods and upgrading to a patched release.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-61460 was published for an insecure direct object reference vulnerability in Krayin CRM through version 2.2.3. The advisory said missing ownership validation in several controllers lets authenticated users edit, update, delete, and reassign other users' CRM records.
A GitHub issue documented that Krayin CRM's Bouncer middleware enforced route-level ACLs but failed to consistently enforce record-level ownership checks in multiple controller methods. The report included exploit details showing that a user could edit another user's lead and transfer ownership by changing the user_id field.
A report on Krayin CRM stated that a systematic record-level authorization flaw was confirmed on 2026-05-26, affecting Lead, Person, Organization, Quote, and Activity entities. The issue allows authenticated users with limited permissions to access, modify, delete, or reassign records owned by other users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.