Executive brief
NextCRM, an open-source customer relationship management platform, contains a security flaw in its product catalog management. While the system is designed to only allow managers and administrators to modify product data, a specific programming interface (API) fails to check these permissions. This allows any standard user with a valid API token to create, change, or delete products, potentially leading to fraudulent pricing, incorrect inventory data, or disruption of sales and invoicing workflows.
Technical details
A Broken Access Control (BAC) vulnerability exists in NextCRM version 0.12.1 within the Model Context Protocol (MCP) implementation. While standard application server actions enforce Role-Based Access Control (RBAC) using a `requireRole` check for 'manager' or 'admin' roles, the MCP handlers located at `/api/mcp/mcp` (specifically `crm_create_product`, `crm_update_product`, and `crm_delete_product`) fail to perform similar authorization checks. An authenticated attacker with a low-privileged 'user' role can generate a Bearer token and interact directly with these API endpoints to perform unauthorized CRUD operations on the `crm_Products` database table. This bypass allows for the modification of product metadata, pricing, and status. The issue is addressed in version 0.12.3.
Affected products
- pdovhomilja nextcrm-app 0.12.1
Timeline
- 2026-06-13: advisory: Vendor advisory published on GitHub
- 2026-07-20: disclosed: CVE published to NVD
- 2026-07-20: patched: Fix available in version 0.12.3