PT-2026-61717 · Nextcrm · Nextcrm
CVE-2026-47130
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
NextCRM versions prior to 0.12.0
Description
Broken Object Level Authorization (BOLA), also known as Insecure Direct Object Reference (IDOR), occurs when an application does not properly verify if a user has permission to access or modify a specific object. In this case, the CRM contact and target update endpoints fail to verify if the authenticated user owns the resource being modified. This allows any authenticated user, including those with a
member role, to arbitrarily modify sensitive CRM contacts and targets belonging to other users or organizations, leading to cross-tenant data tampering.Recommendations
Update to version 0.12.0.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextcrm