VYPR
High severity8.1NVD Advisory· Published Jul 20, 2026· Updated Jul 22, 2026

CVE-2026-47129

CVE-2026-47129

Description

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the activateUser and deactivateUser Next.js Server Actions of NextCRM. The application fails to verify if the requesting user holds the admin role. Consequently, any authenticated user (even those with the lowest member or viewer roles) can arbitrarily activate or deactivate any user account in the system, including the main administrator. Version 0.12.0 fixes the issue.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.