CVE-2026-55544 is an authorization bypass vulnerability in NextCRM's MCP campaign tools. A low-privileged authenticated user with a valid MCP API token can enumerate all campaigns, read campaign details, update or delete campaigns owned by other users, modify campaign templates and steps, and potentially trigger or pause campaign delivery. This vulnerability affects NextCRM version 0.12.1 and is fixed in [truncated]
A high-severity vulnerability exists in NextCRM, an open-source customer relationship management software. The issue, identified as CVE-2026-47130, affects versions prior to 0.12.0 and is classified as a Broken Object Level Authorization (BOLA/IDOR) vulnerability. This vulnerability allows any authenticated user, even those with a standard 'member' role, to arbitrarily modify sensitive CRM contacts and ta [truncated]
CVE-2026-47129 is a high-severity vulnerability in NextCRM, an open-source customer relationship management software. Versions prior to 0.12.0 are affected by a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js Server Actions. This vulnerability allows any authenticated user, including those with the lowest `member` or `viewer` roles, to arbitrarily activate or d [truncated]