CVE-2026-38526 is an authenticated arbitrary file upload vulnerability in Webkul Krayin CRM v2.2.x. The flaw is present in the /admin/tinymce/upload endpoint, which can be abused to upload a crafted PHP file. If the uploaded file is stored in a web-accessible location and processed by the server as PHP, an authenticated attacker can use the upload functionality to achieve arbitrary code execution on the target system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
13 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This is a small standalone Python exploit repository consisting of exploit.py, a French README, requirements.txt, and an MIT license. The sole code entry point uses requests to establish a session, retrieve a CSRF token from the configurable login path, authenticate with supplied Krayin credentials, and upload a randomly named .php file to the configurable TinyMCE upload route. Its embedded PHP payload invokes system() on a GET or POST cmd value. The exploit then attempts to identify the shell's public URL from upload information and several hard-coded storage/upload prefixes, requests it with the requested command, and extracts marked command output. The README describes the issue as CVE-2026-38526 affecting Webkul Krayin CRM <=2.2.x, with arbitrary upload leading to RCE. This is functional offensive exploit code rather than a detector; it leaves a persistent shell unless the operator removes the uploaded file.
This is a small standalone Python exploit repository containing one executable script, exploit.py, plus a French README, requirements file, license, and gitignore. It targets the claimed CVE-2026-38526 issue in Webkul Krayin CRM <= 2.2.x. The script uses requests to establish a session, scrape a Laravel CSRF token from /admin/login, authenticate with supplied credentials, upload a randomly named PHP shell to /admin/tinymce/upload, and attempt to identify the shell beneath several public storage/upload URL prefixes. It then invokes a user-selected command through the shell's cmd parameter and extracts output using a randomized PWNED marker. The code is an operational authenticated RCE exploit rather than a scanner: it creates a persistent server-side webshell and supports arbitrary command execution. No fixed external host, IP address, or callback endpoint is embedded; the target base URL and credentials are operator supplied. The CVE and affected-version claim are taken from repository content and are not independently verified here.
This three-file repository consists of an MIT license, a detailed README, and one executable Bash proof-of-concept, nexus_privesc_public.sh. The script embeds Python to manually construct raw Git blob, tree, and commit objects, bypassing normal Git client validation of dangerous tree entry names. It creates a public Gitea repository named rce, marks it as a template through the local Gitea API, and force-pushes a commit whose nested tree entries are named '..'. The intended vulnerable component is a custom root-owned gitea-template-sync.service on the Hack The Box Nexus host. If that service traverses Git tree entries and builds output paths with unsanitized os.path.join() calls, the nested '..' tree structure resolves outside its staging directory and writes the generated attacker public key into /root/.ssh/authorized_keys. After waiting 70 seconds for the stated synchronization timer, the script attempts root SSH to the user-supplied target IP. This is an operational, environment-specific local privilege-escalation exploit rather than a generic Gitea vulnerability: success depends on the custom service behavior, precise traversal depth, permissive Git object acceptance, valid Gitea credentials, and root SSH availability. The README mentions CVE-2026-38526 only as an earlier, unrelated Krayin CRM foothold stage; the included code does not exploit that CVE.
This 16-file repository is an HTB Nexus walkthrough and operational multi-stage exploit kit rather than a single framework module. Its primary exploit assets are a Burp multipart request and embedded PHP webshell for the documented Krayin CRM upload flaw (CVE-2026-38526), a Python reverse-shell client, and a Python script that writes raw Git blob/tree/commit objects. The Git payload creates nested '..' tree entries so that a vulnerable root-run gitea-template-sync service resolves a repository-controlled path outside its intended template directory and writes an SSH public key under root's .ssh directory. The documented chain starts with virtual-host enumeration, retrieves exposed credentials from Gitea history, uploads and invokes the PHP webshell on billing.nexus.htb, obtains www-data execution and then jones SSH credentials from /var/www/krayin/.env, and finally pushes the malicious repository to Gitea for root privilege escalation. Supporting Bash scripts perform broad local Linux and service enumeration; assets include credentials and placeholders, while the two scan-output files are empty. Notably, the PHP source is stored as shell.php.png in the archive despite documentation referring to shell.php; the same PHP payload is directly included in burp_request.txt.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-38526 affecting Krayin CRM <= 2.2.x. The repo contains three files: a single Python exploit script (CVE-2026-38526.py), a README with usage and exploitation notes, and a minimal requirements.txt listing requests. The exploit is not part of a larger framework. The main script automates an authenticated unrestricted file upload attack against the TinyMCE upload feature. Its flow is: (1) request /admin/login and scrape a CSRF token from the HTML, (2) submit admin credentials to authenticate and preserve session state, (3) request /admin/dashboard to obtain a fresh CSRF token or fall back to the XSRF-TOKEN cookie, (4) POST a PHP payload disguised with MIME type image/jpeg to /admin/tinymce/upload, (5) parse the JSON response for the uploaded file location, and (6) invoke the uploaded webshell by sending a cmd GET parameter to execute arbitrary system commands. The exploit capability is full authenticated remote code execution via uploaded PHP webshell. The embedded payload is simple but functional: <?php system($_GET['cmd']); ?>. This makes the exploit operational rather than a mere detector, because it performs exploitation end-to-end and immediately executes attacker-supplied commands. The README also documents post-exploitation examples such as reading /etc/passwd and launching a reverse shell, though those payloads are user-supplied examples rather than hardcoded behavior in the script. Fingerprintable targets and endpoints are centered on the Krayin CRM admin interface: /admin/login, /admin/dashboard, and especially /admin/tinymce/upload. The uploaded artifact is named shell.php, and command execution occurs through the cmd query parameter on the returned uploaded-file URL. Overall, the repository's purpose is to provide a concise authenticated RCE PoC for vulnerable Krayin CRM deployments.
Repository contains a single Python exploit script, a README, and a license. The exploit targets CVE-2026-38526 in Krayin CRM v2.2.x and is a real authenticated web RCE proof of concept rather than a scanner. The script uses requests and BeautifulSoup to automate the full attack chain: initialize an HTTP session with browser-like headers, fetch /admin/login to extract a CSRF token, authenticate with supplied username/password, obtain a fresh upload token from /admin/mail/compose or /admin/mail/inbox?openModal=true, upload a PHP web shell named shell.php via the CRM mail-related upload feature, parse the returned JSON for the uploaded file location, and then invoke the shell with a cmd parameter to execute arbitrary system commands. The README example shows the uploaded file landing under /storage/tinymce/...php and demonstrates execution of the id command. The payload is a basic PHP command shell using system($_GET['cmd']), so the exploit provides direct command execution but not an advanced post-exploitation framework. Overall, this is an operational authenticated file-upload-to-RCE exploit for a web application, with hardcoded shell content and attacker-supplied command execution.
Repository contains a single substantial Python exploit script, plus README, LICENSE, and requirements. The script targets Krayin CRM v2.2.x and claims CVE-2026-38526, an authenticated remote code execution issue via TinyMCE file upload bypass. It is a real exploit rather than a detector: it accepts target URL and credentials, performs authenticated interaction with the web application, uploads a PHP payload, verifies deployment, and can launch an interactive command shell against the uploaded web shell. The code is structured with enums for shell/output modes, dataclasses for configuration and results, output helpers, and a PayloadGenerator containing multiple embedded PHP shell variants. Visible payloads include a basic command shell using the cmd parameter and an advanced shell using the c parameter with multiple PHP execution-function fallbacks. The script also supports a generate-only mode to write a shell payload to disk locally, JSON/text output modes, retry/proxy/header options, and optional SSL verification control. No hardcoded external C2, IPs, or third-party callback endpoints are present in the provided content; network interaction is directed at a user-supplied Krayin CRM target. Overall, this is an operational authenticated web exploit for deploying a persistent PHP web shell on a vulnerable Krayin CRM instance.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-38526 affecting Krayin CRM v2.2.x. The repository contains three files: README.md with usage examples and vulnerability description, requirements.txt listing requests and beautifulsoup4, and exploit.py as the sole executable component. The exploit targets an authenticated unrestricted file upload flaw in Krayin CRM's TinyMCE upload functionality. Its workflow is: authenticate to the admin panel using supplied email/password, obtain session state and likely a CSRF token, upload a PHP payload through /admin/tinymce/upload, recover the resulting shell URL, and then either present that URL to the operator for web-shell access or trigger the uploaded reverse shell. The Python script defines a KrayinExploit class and supports two payload modes. Default mode generates a simple PHP web shell that executes commands from the cmd query parameter using system(). Reverse-shell mode generates a more capable PHP payload that uses fsockopen() to connect back to an operator-supplied host and port, then launches sh -i through proc_open() and relays I/O over the socket. The attack() wrapper authenticates, uploads, and either prints the shell URL or triggers the reverse shell while instructing the operator to start a netcat listener. The exploit is operational rather than just demonstrative because it contains complete end-to-end exploitation logic and working payloads, but it is not obviously part of a larger framework and does not expose extensive payload customization beyond lhost/lport. The primary fingerprintable application endpoints are /admin/login, /admin/dashboard, and /admin/tinymce/upload. The exploit also creates an attacker-defined outbound TCP callback target for reverse-shell operation.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-38526 targeting Webkul Krayin CRM 2.2.x. The repository contains 5 files: a README with usage instructions, a Python exploit script (poc.py), requirements.txt, LICENSE, and .gitignore. The only meaningful code is in poc.py, making it the clear entry point. The exploit workflow is straightforward: it creates a requests session, fetches /admin/login to obtain cookies and an HTML form CSRF token, submits valid user credentials, then requests /admin/dashboard to obtain a second CSRF token required for the upload action. It next sends a multipart POST request to /admin/tinymce/upload with a file named webshell.php containing a minimal PHP command-execution webshell. The script expects a JSON response containing a location field, which it treats as the uploaded file URL. Finally, it sends a GET request to that uploaded file with a cmd parameter containing a Python3 reverse shell one-liner. Main exploit capability: authenticated remote code execution via arbitrary file upload leading to webshell deployment and reverse shell execution. This is not merely a detector; it performs full exploitation. The exploit is operational but not highly polished: it requires valid credentials, assumes HTTP rather than HTTPS, and contains a hardcoded reverse-shell callback IP (10.10.17.34) and port (9001) in the actual shell command, even though CLI arguments exist for attacker IP and port. As written, the ip and port arguments are parsed but not interpolated into the reverse shell payload, which limits flexibility unless the operator edits the script. Fingerprintable targets and artifacts include the Krayin admin endpoints /admin/login, /admin/dashboard, and especially /admin/tinymce/upload; session-related cookies XSRF-TOKEN and krayin_crm_session; CSRF token fields/headers; the uploaded filename webshell.php; and the cmd query parameter used to trigger command execution. Overall, the repository’s purpose is to demonstrate authenticated exploitation of the vulnerable TinyMCE upload functionality in Krayin CRM by uploading and invoking a PHP webshell to gain a reverse shell.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-38526 affecting Krayin CRM 2.2.x and earlier. The repo contains one executable script (CVE-2026-38526.py), a README with usage and exploit flow documentation, and a minimal requirements.txt listing requests. The exploit is not part of a larger framework. Its workflow is straightforward and operational: it first requests /admin/login, extracts a CSRF token from the HTML, and authenticates using supplied admin credentials. It then requests /admin/dashboard to obtain a fresh CSRF token, falling back to the XSRF-TOKEN cookie if needed. After authentication, it abuses the vulnerable POST /admin/tinymce/upload endpoint by uploading a PHP payload named shell.php while spoofing the MIME type as image/jpeg. The script expects a JSON response containing a location field that points to the uploaded file. It then sends a GET request to that returned URL with the cmd parameter to execute arbitrary system commands through the uploaded PHP webshell. Main exploit capability: authenticated unrestricted file upload leading to remote code execution. The payload is a minimal PHP command webshell: <?php system($_GET['cmd']); ?>. The script supports arbitrary command execution via the -c argument, defaulting to id, and also prints a curl command for manual reuse of the uploaded shell. The README additionally demonstrates how the exploit could be used to run a reverse shell command, but the exploit itself does not embed a reverse shell payload by default. Overall, this is a real exploit rather than a detector. It requires valid admin credentials and a vulnerable Krayin CRM deployment where uploaded PHP files are web-accessible and executable.
This repository contains a single Python exploit script, CVE-2026-38526.py, targeting an authenticated file upload vulnerability in Krayin CRM v2.2.x that can be leveraged for remote code execution. The script is not part of a larger exploit framework. Operational flow: it creates an HTTP client with TLS verification disabled, requests /admin/login, parses the HTML to extract a CSRF token from the first input element, submits supplied email/password credentials to the same login endpoint, retrieves the XSRF-TOKEN cookie from the authenticated response, and then uploads an attacker-provided local file to /admin/tinymce/upload using multipart/form-data. The upload request sets the X-XSRF-TOKEN header from the cookie value. On success, the script prints the JSON field location, which is the server-side path/URL of the uploaded file. Main capability: authenticated arbitrary file upload. The exploit itself does not execute commands directly; instead, it enables code execution if the uploaded file is a server-executable payload such as a PHP webshell and the application stores it in a web-accessible executable location. The MIME type is hardcoded as image/jpeg, suggesting an attempt to bypass superficial content checks while still sending arbitrary file contents. Repository structure is minimal: one standalone Python entry point using asyncio, httpx, argparse, urllib.parse, BeautifulSoup, and json. There are no auxiliary modules, persistence features, scanning logic, or post-exploitation automation. This is best classified as an operational proof-of-concept exploit for authenticated web-based file upload leading to potential RCE.
This repository is a small, focused exploit PoC for CVE-2026-38526 affecting Krayin CRM 2.2.x and earlier. It contains two files: a README describing usage and exploit goals, and a single Python entry point, exploit.py, implementing the attack flow. The exploit is a credentialed web attack against Krayin CRM’s administrative interface. It logs into /admin/login using supplied email and password, extracts a Laravel-style CSRF token from the login page, then refreshes the token by requesting /admin/mail/inbox. After authentication, it abuses the TinyMCE upload endpoint at /admin/tinymce/upload to upload a PHP webshell disguised with a double extension, shell.png.php, while declaring an image MIME type. The uploaded payload is a minimal PHP command-execution webshell that runs system($_GET['cmd']). Once upload succeeds, the script parses the JSON response to recover the uploaded file location and then uses the resulting shell URL for post-exploitation. It supports two execution modes: single-command execution via HTTP GET with the cmd parameter, or a reverse shell mode that builds a bash one-liner, base64-encodes it, and executes it through the webshell. The reverse shell connects back to an attacker-supplied host and port using /dev/tcp. Repository structure is minimal and operational rather than research-oriented: one README and one Python exploit script. The code uses requests for session handling and HTTP interactions, BeautifulSoup plus regex fallback for CSRF extraction, argparse for CLI handling, and base64 for obfuscating the reverse shell command. This is a real exploit, not a detector, and it provides practical post-authentication RCE capability with a hardcoded but functional payload.
This repository is a small standalone proof-of-concept exploit for CVE-2026-38526 affecting Webkul Krayin CRM v2.2.x. It contains two files: a README describing the vulnerability and usage, and a single Python entry-point script, exploit.py. The exploit is not part of a larger framework. The exploit performs a full authenticated attack chain: it first requests /admin/login to scrape the Laravel CSRF form token, reads the XSRF-TOKEN cookie from the session, then submits credentials to /admin/login using AJAX-style headers. After authentication, it sends a multipart upload to /admin/tinymce/upload with a file named shell.php containing a minimal PHP webshell payload (<?php system($_GET['cmd']); ?>) while spoofing the MIME type as image/jpeg. If the server returns a location field in JSON, the script appends ?cmd=<command> to that URL and triggers execution, printing the resulting command output. Main exploit capability: authenticated arbitrary command execution on the target server via unrestricted PHP file upload and subsequent webshell invocation. The exploit assumes uploaded files are stored in a web-accessible location, documented in the README as /storage/tinymce/, and that the server executes uploaded PHP. The script requires valid credentials and a target base URL. It is operational rather than just demonstrative because it automates login, upload, and command execution end-to-end.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.