CVE•Published 2026-04-14•Modified 2026-04-14•1 article on news•6 live references•NVD data
CVE-2026-38526
Vulnerability data via NVD (ingested)
CVSS v3.1
9.9
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS percentile
—
Weaknesses (CWE)
Description
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.
Timeline
Published 2026-04-14
Modified 2026-04-14
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
More intel sources (5)
Shodan report
vuln:CVE-2026-38526Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-38526Censys host search filtered to this CVE id.
grep.app
CVE-2026-38526Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-38526GitHub code search for direct mentions.
Google dork
"CVE-2026-38526" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (8)
CVE-2026-385268 repos
rix4uni/medium-writeupsGo
This repository updates latest Bug Bounty medium writeups every 10 minutes, https://readmedium.com/Medium_URL, https://archive.ph/Medium_URL, https://freedium.cfd/Medium_URL
DarkFunct/TK-CVE-RepoPython
TK-CVE-Repo
zulloper/cve-pocPython
CVE POC repo 자동 수집기
TREXNEGRO/Security-Advisoriesunknown
NathanHimself/CVE-2026-38526-PoCPython
CVE-2026-38526 | Krayin CRM v2.2.x Authenticated RCE - Unrestricted PHP File Upload via TinyMCE
Fakechippies/POC-HunterGo
POC-Hunter is a Go CLI that hunts CVEs by product/version and maps them to publicly available Proof-of-Concept exploits, with direct CVE-to-POC lookup support.
CerberusMrXi/KrayinCRM-RCE-Exploit-CVE-2026-38526Python
CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads, auto shell generation, and verific…
pawpic/CVE-2026-38526-POCPython
Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution