PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-55544 pdovhomilja CVE debrief

CVE-2026-55544 is an authorization bypass vulnerability in NextCRM's MCP campaign tools. A low-privileged authenticated user with a valid MCP API token can enumerate all campaigns, read campaign details, update or delete campaigns owned by other users, modify campaign templates and steps, and potentially trigger or pause campaign delivery. This vulnerability affects NextCRM version 0.12.1 and is fixed in version 0.12.2. The vulnerability has a CVSS score of 7.6 and is classified as HIGH severity.

Vendor
pdovhomilja
Product
nextcrm-app
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-20
Original CVE updated
2026-07-22
Advisory published
2026-07-20
Advisory updated
2026-07-22

Who should care

Users of NextCRM version 0.12.1 should apply the patch in version 0.12.2. Low-privileged users with MCP API tokens are at risk of exploitation. Operators and administrators of NextCRM deployments should review their configurations and ensure that access to MCP API tokens is restricted. Vulnerability management and security teams should prioritize patching and monitor for suspicious campaign modifications.

Technical summary

The MCP campaign tools in NextCRM 0.12.1 expose campaign read and write operations over the network using user-generated Bearer API tokens. Multiple MCP campaign handlers ignore the authenticated user ID and query or mutate campaigns only by object ID, allowing low-privileged authenticated users to access and modify campaigns beyond their authorization. The vulnerability is due to inadequate authorization checks in the MCP campaign handlers.

Defensive priority

Apply the patch in NextCRM version 0.12.2. Restrict access to MCP API tokens. Monitor for suspicious campaign modifications and review campaign permissions.

Recommended defensive actions

  • Apply the patch in NextCRM version 0.12.2
  • Restrict access to MCP API tokens
  • Monitor for suspicious campaign modifications
  • Review and update campaign permissions
  • Implement additional access controls
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-20T22:17:16.407Z and was last modified on 2026-07-22T14:17:21.293Z. The NVD entry is currently Deferred. The source item URL for CVE-2026-55544 is available. The official CVE record and NVD detail page provide additional information. However, the scope of affected products and components is not explicitly stated, and defenders should verify the impact on their specific deployments.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T22:17:16.407Z and has not been modified since then. The NVD entry is currently Deferred.