NVD HIGH: CVE-2026-100885 — A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unk...
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this is
CVE-2026-100885