---
id: CVE-2026-61460
title: >-
  Krayin CRM through 2.2.3 contains an insecure direct object reference
  vulnerability in LeadController, PersonController, OrganizationController,
  QuoteController, and ActivityController that allows authenticated users to
  edit, update, or …
summary: >-
  Krayin CRM through 2.2.3 contains an insecure direct object reference
  vulnerability in LeadController, PersonController, OrganizationController,
  QuoteController, and ActivityController that allows authenticated users to
  edit, update, or …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-639
published: '2026-07-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61460'
references:
  - url: 'https://github.com/krayin/laravel-crm/issues/2559'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/krayin/laravel-crm/pull/2567'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/krayin-crm-insecure-direct-object-reference-via-controllers
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00506
epssPercentile: 0.40597
ingestedAt: '2026-07-11T20:15:26.434Z'
---

## Overview

Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or delete records owned by other users. Attackers can modify CRM records and reassign ownership by exploiting missing record-level ownership validation in edit, update, and destroy methods.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
