Vulnerability Description
An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function
CVSS Score
8.1
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Related Weaknesses (CWE)
References
- https://drive.google.com/file/d/1yBdvbrXGf9fsFckmK9zTe2v8_vDtdicH/view
- https://github.com/cybercrewinc/CVE-2026-36340
- https://github.com/krayin/laravel-crm/releases/tag/v2.1.6
- https://github.com/cybercrewinc/CVE-2026-36340
FAQ
What is CVE-2026-36340?
CVE-2026-36340 is a vulnerability with a CVSS score of 8.1 (HIGH). An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function
How severe is CVE-2026-36340?
CVE-2026-36340 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-36340?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.