HIGH
pdovhomilja
CVE published 2026-07-20
CVE-2026-55544
CVE-2026-55544 is an authorization bypass vulnerability in NextCRM's MCP campaign tools. A low-privileged authenticated user with a valid MCP API token can enumerate all campaigns, read campaign details, update or delete campaigns owned by other users, modify campaign templates and steps, and potentially trigger or pause campaign delivery. This vulnerability affects NextCRM version 0.12.1 and is fixed in [truncated]