Authorization Flaw in NextCRM Exposes Campaign Operations
CVE-2026-55544

7.6HIGH

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-55544?

NextCRM, an open-source customer relationship management software, has a vulnerability in version 0.12.1 impacting its MCP campaign tools. The flaw allows authenticated low-privileged users with valid Bearer API tokens to perform unauthorized operations on campaigns. Although the application attempts to restrict users to their own campaigns, several MCP campaign handlers fail to check the authenticated user's ID, enabling them to enumerate campaigns, access details, and modify or delete campaigns owned by others. This exposes significant risks, including the potential to alter campaign settings and disrupt marketing activities. The issue was addressed in version 0.12.2.

Affected Version(s)

nextcrm-app = 0.12.1

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.