Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 18:20
Updated : 2026-09-14 21:17
NVD link : CVE-2026-90944
Mitre link : CVE-2026-90944
CVE.ORG link : CVE-2026-90944
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
