High severity8.1NVD Advisory· Published Jul 20, 2026· Updated Jul 22, 2026
CVE-2026-47129
CVE-2026-47129
Description
NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the activateUser and deactivateUser Next.js Server Actions of NextCRM. The application fails to verify if the requesting user holds the admin role. Consequently, any authenticated user (even those with the lowest member or viewer roles) can arbitrarily activate or deactivate any user account in the system, including the main administrator. Version 0.12.0 fixes the issue.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.