Authorization Flaw in NextCRM Exposes Campaign Operations
CVE-2026-55544
7.6HIGH
What is CVE-2026-55544?
NextCRM, an open-source customer relationship management software, has a vulnerability in version 0.12.1 impacting its MCP campaign tools. The flaw allows authenticated low-privileged users with valid Bearer API tokens to perform unauthorized operations on campaigns. Although the application attempts to restrict users to their own campaigns, several MCP campaign handlers fail to check the authenticated user's ID, enabling them to enumerate campaigns, access details, and modify or delete campaigns owned by others. This exposes significant risks, including the potential to alter campaign settings and disrupt marketing activities. The issue was addressed in version 0.12.2.
Affected Version(s)
nextcrm-app = 0.12.1
