Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

NextCRM MCP API Missing Role Checks in Product Operations

NextCRM version 0.12.1 fails to enforce role-based access controls in its MCP product tools API, allowing any authenticated low-privileged user with an MCP API token to create, modify, archive, or delete products in the shared CRM catalog. The vulnerability was fixed in version 0.12.3.

Disclosed 20 July 2026 · Record updated 13 September 2026

Impact

Low-privileged authenticated users can bypass role-based access controls to manipulate shared product catalog data through the MCP API.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55550