← Back to browse · API

CVE-2026-38526

Severity
CRITICAL
CVSS
9.9
EPSS
0.03824
Risk score
40.94
CISA KEV
No
PoC
Yes
Published
2026-04-14
Modified
2026-04-14
First seen
2026-08-07
Aliases
EUVD-2026-22296, GHSA-J8GJ-MW5G-642G
Products
n/a:n/a n/a
Sources
packetstorm 2ade931fd63f403e0e563936|CVE-2026-38526
packetstorm 6b448f77db4c5808a6c49167|CVE-2026-38526
euvd EUVD-2026-22296

Description

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

References