Feed/CVE-2026-38526
CVE-2026-38526CRITICALCVSS 9.9

CVE-2026-38526

Published Apr 14, 2026·Updated Jun 17, 2026

NVD Description

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

Public Exploits & PoCs9 found

PoC: CVE-2026-38526-PoC

CVE-2026-38526 | Krayin CRM v2.2.x Authenticated RCE - Unrestricted PHP File Upload via TinyMCE

1

[POC] GHSA-3mgp-fx93-9xv5 — CVE-2026-38526-POC

Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution

PoC: htb-labs-nexus

Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.

PoC: CVE-2026-38526-KrayinCRM-RCE

CVE-2026-38526 Exploit | by infrar3d

PoC: KrayinCRM-RCE-Exploit-CVE-2026-38526

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads, auto shell generation, and verification. Author: Sudeepa Wanigarathna. For authorized testing only.

PoC: CVE-2026-38526-PoC-htb-nexus

A PoC script for CVE-2026-38526, RCE via a file upload vulnerability in the /admin/tinymce/upload endpoint of webkul krayin 2.2.x

PoC: CVE-2026-38526

Automated exploit for Krayin CRM ≤ 2.2.x.

PoC: CVE-2026-38526-Exploit

Exploit for Authenticated Remote Code Execution (RCE) in Krayin CRM v2.2.x (CVE-2026-38526)

PoC: Hack-The-Box-Nexus-Findings-Report

HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and privilege escalation via Gitea template sync directory traversal. Mapped to MITRE ATT&CK and NSA D3FEND frameworks with actionable remediation roadmap and full evidence appendix.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free