PT-2026-61736 · Nextcrm · Nextcrm

CVE-2026-55544

·

Published

2026-07-20

·

Updated

2026-07-21

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions NextCRM version 0.12.1
Description The MCP campaign tools expose read and write operations over the network using user-generated Bearer API tokens (nxtc ...). The application fails to properly validate the authenticated user ID in multiple MCP campaign handlers, querying or mutating campaigns based solely on the object ID. This allows a low-privileged authenticated user with a valid MCP API token to enumerate, read, update, or delete campaigns belonging to other users, as well as modify campaign templates and steps, and potentially trigger or pause campaign delivery.
Recommendations Update to version 0.12.2.

Fix

Missing Authorization

Improper Access Control

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55544

Affected Products

Nextcrm