CVE-2026-61460

Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or delete records owned by other users. Attackers can modify CRM records and reassign ownership by exploiting missing record-level ownership validation in edit, update, and destroy methods.
Configurations

No configuration.

History

10 Jul 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 19:17

Updated : 2026-07-10 20:16


NVD link : CVE-2026-61460

Mitre link : CVE-2026-61460

CVE.ORG link : CVE-2026-61460


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key