CVE-2026-100884

Published: Set 28, 2026 Last Modified: Set 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:
LOW 2,1
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 4,3
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
MEDIUM 4,0
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: partial
Integrity: none
Availability: none

Description

AI Translation Available

A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.

99

Improper Control of Resource Identifiers ('Resource Injection')

Draft
Common Consequences
Security Scopes Affected:
Confidentiality Integrity
Potential Impacts:
Read Application Data Modify Application Data Read Files Or Directories Modify Files Or Directories
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/carlosalbertotuma/advisory/blob/main/advisory-06-IDOR-Email-…
https://github.com/krayin/laravel-crm/
https://github.com/krayin/laravel-crm/commit/13d6988cda8d69ece45ee1890effc90a7f…
https://github.com/krayin/laravel-crm/issues/2624
https://github.com/krayin/laravel-crm/pull/2627
https://github.com/krayin/laravel-crm/releases/tag/v2.2.6
https://vuldb.com/cve/CVE-2026-100884
https://vuldb.com/submit/916218
https://vuldb.com/vuln/410814
https://vuldb.com/vuln/410814/cti