NextCRM MCP API Missing Role Checks in Product Operations
NextCRM version 0.12.1 fails to enforce role-based access controls in its MCP product tools API, allowing any authenticated low-privileged user with an MCP API token to create, modify, archive, or delete products in the shared CRM catalog. The vulnerability was fixed in version 0.12.3.
Disclosed 20 July 2026 · Record updated 13 September 2026
Impact
Low-privileged authenticated users can bypass role-based access controls to manipulate shared product catalog data through the MCP API.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55550
