CVE-2026-90944
nicheUnauthenticated Email Injection in Krayin CRM via /admin/mail/inbound-parse
Krayin CRM through version 2.2.6 fails to enforce authentication on the POST /admin/mail/inbound-parse endpoint, which is intended to receive inbound mail for the CRM. An unauthenticated remote attacker can POST a crafted RFC 2822 message with forged sender addresses and headers, injecting arbitrary emails into the CRM's inbox — including messages that appear as replies to existing conversation threads. This enables spoofed communications, thread hijacking, and social engineering against sales and support teams who trust the inbox contents, with high impact to integrity (CVSS 4.0: 8.8). Any organization self-hosting Krayin CRM up to and including 2.2.6 with the endpoint reachable is affected. No public proof of concept is known and the flaw is not on the CISA KEV catalog, so exploitation status is currently none known.
What to do: Upgrade Krayin CRM beyond 2.2.6 once Webkul ships a fixed release, and check their advisories for the patch. Until then, block or restrict unauthenticated access to POST /admin/mail/inbound-parse at the reverse proxy or WAF, and require the endpoint to be reachable only from your inbound-mail provider's IPs. Audit CRM inboxes for injected or forged messages and brief staff that inbox contents may not be authentic.
| Webkul Krayin CRM | through 2.2.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads.
- Weakness
- CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.