CVE-2026-55550
NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Nor
CVSS
7.1
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 20, 2026 · Last modified: Jul 20, 2026 · CWE-269 · CWE-284 · CWE-862
Not enough EPSS history yet.
NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, update, and deletion to `manager` and `admin` roles. However, in version 0.12.1, the MCP product tools expose the same write operations through `/api/mcp/mcp` using user-generated Bearer tokens and do not enforce role checks. Any authenticated low-privileged user who can generate an MCP API token can create, modify, archive, or soft-delete products in the shared CRM product catalog. Version 0.12.3 contains a fix.