PT-2026-61736 · Nextcrm · Nextcrm
CVE-2026-55544
·
Published
2026-07-20
·
Updated
2026-07-21
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
NextCRM version 0.12.1
Description
The MCP campaign tools expose read and write operations over the network using user-generated Bearer API tokens (
nxtc ...). The application fails to properly validate the authenticated user ID in multiple MCP campaign handlers, querying or mutating campaigns based solely on the object ID. This allows a low-privileged authenticated user with a valid MCP API token to enumerate, read, update, or delete campaigns belonging to other users, as well as modify campaign templates and steps, and potentially trigger or pause campaign delivery.Recommendations
Update to version 0.12.2.
Fix
Missing Authorization
Improper Access Control
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcrm