Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 21, 2026
NextCRM has Broken Access Control in Server Actions that allows any authenticated user to deactivate/activate arbitrary accounts
CVE-2026-47129
Description
NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the activateUser and deactivateUser Next.js Server Actions of NextCRM. The application fails to verify if the requesting user holds the admin role. Consequently, any authenticated user (even those with the lowest member or viewer roles) can arbitrarily activate or deactivate any user account in the system, including the main administrator. Version 0.12.0 fixes the issue.
Affected products
2- Range: <0.12.0
Patches
Vulnerability mechanics
References
2- github.com/pdovhomilja/nextcrm-app/releases/tag/v0.12.0mitrex_refsource_MISC
- github.com/pdovhomilja/nextcrm-app/security/advisories/GHSA-gm7p-f88p-vhfrmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.