SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-90944

HIGH · CVSS 8.2 EPSS 0.71% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Krayin CRM versions up to 2.2.6 are vulnerable due to an unauthenticated exposure of the POST /admin/mail/inbound-parse endpoint, enabling attackers to inject arbitrary emails into the CRM inbox. This flaw allows for the manipulation of email content, including forged sender information and replies to existing threads, potentially leading to data integrity issues and phishing attacks. Organizations using Krayin CRM should prioritize patching this vulnerability to safeguard against unauthorized email injections.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90944
Severity
HIGH
CVSS
8.2
EPSS
0.71%

Original NVD Description

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads.