PatchSiren cyber security CVE debrief
CVE-2026-55544 pdovhomilja CVE debrief
CVE-2026-55544 is an authorization bypass vulnerability in NextCRM's MCP campaign tools. A low-privileged authenticated user with a valid MCP API token can enumerate all campaigns, read campaign details, update or delete campaigns owned by other users, modify campaign templates and steps, and potentially trigger or pause campaign delivery. This vulnerability affects NextCRM version 0.12.1 and is fixed in version 0.12.2. The vulnerability has a CVSS score of 7.6 and is classified as HIGH severity.
- Vendor
- pdovhomilja
- Product
- nextcrm-app
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-07-22
Who should care
Users of NextCRM version 0.12.1 should apply the patch in version 0.12.2. Low-privileged users with MCP API tokens are at risk of exploitation. Operators and administrators of NextCRM deployments should review their configurations and ensure that access to MCP API tokens is restricted. Vulnerability management and security teams should prioritize patching and monitor for suspicious campaign modifications.
Technical summary
The MCP campaign tools in NextCRM 0.12.1 expose campaign read and write operations over the network using user-generated Bearer API tokens. Multiple MCP campaign handlers ignore the authenticated user ID and query or mutate campaigns only by object ID, allowing low-privileged authenticated users to access and modify campaigns beyond their authorization. The vulnerability is due to inadequate authorization checks in the MCP campaign handlers.
Defensive priority
Apply the patch in NextCRM version 0.12.2. Restrict access to MCP API tokens. Monitor for suspicious campaign modifications and review campaign permissions.
Recommended defensive actions
- Apply the patch in NextCRM version 0.12.2
- Restrict access to MCP API tokens
- Monitor for suspicious campaign modifications
- Review and update campaign permissions
- Implement additional access controls
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-20T22:17:16.407Z and was last modified on 2026-07-22T14:17:21.293Z. The NVD entry is currently Deferred. The source item URL for CVE-2026-55544 is available. The official CVE record and NVD detail page provide additional information. However, the scope of affected products and components is not explicitly stated, and defenders should verify the impact on their specific deployments.
Official resources
-
CVE-2026-55544 CVE record
CVE.org
-
CVE-2026-55544 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T22:17:16.407Z and has not been modified since then. The NVD entry is currently Deferred.