CVE-2026-100885 | Krayin laravel-crm up to 2.2.4 admin-config-setup API Endpoint CanInstall.php authorization

SecurityVulns

A vulnerability described as critical has been identified in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass.

This vulnerability is cataloged as CVE-2026-100885. The attack may be launched remotely. Furthermore, there is an exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More