PT-2026-61737 · Nextcrm · Nextcrm

CVE-2026-55550

·

Published

2026-07-20

·

Updated

2026-07-21

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions NextCRM versions 0.12.1 through 0.12.2
Description NextCRM allows authenticated low-privileged users to perform unauthorized write operations on the shared CRM product catalog. While standard application server actions restrict product creation, updates, and deletions to manager and admin roles, the MCP product tools fail to enforce these role checks. An attacker with a user-generated Bearer token can use the /api/mcp/mcp endpoint to create, modify, archive, or soft-delete products.
Recommendations Update to version 0.12.3.

Exploit

Fix

Improper Privilege Management

Improper Access Control

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55550

Affected Products

Nextcrm