CVE-2026-97895 | krayin laravel-crm up to 2.2.5 User Management UserController.php role_id privileges management (Issue 2616)
A vulnerability classified as critical was found in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing a manipulation of the argument role_id can lead to improper privilege management.
This vulnerability is handled as CVE-2026-97895. The attack can be executed remotely. Additionally, an exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More