CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2026-47129

HIGH
8.1
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-07-20
Last Modified2026-07-22
Data SourcesNVD

Vulnerability Description

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js Server Actions of NextCRM. The application fails to verify if the requesting user holds the `admin` role. Consequently, any authenticated user (even those with the lowest `member` or `viewer` roles) can arbitrarily activate or deactivate any user account in the system, including the main administrator. Version 0.12.0 fixes the issue.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相關漏洞威脅